ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 117 - 312-40 discussion

Report
Export

Martin Sheen is a senior cloud security engineer in SecGlob Cloud Pvt. Ltd. Since 2012, his organization has been using AWS cloud-based services. Using an intrusion detection system and antivirus software, Martin noticed that an attacker is trying to breach the security of his organization. Therefore, Martin would like to identify and protect the sensitive data of his organization. He requires a fully managed data security service that supports S3 storage and provides an inventory of publicly shared buckets, unencrypted buckets, and the buckets shared with AWS accounts outside his organization. Which of the following Amazon services fulfills

Martin's requirement?

A.
Amazon GuardDuty
Answers
A.
Amazon GuardDuty
B.
Amazon Macie
Answers
B.
Amazon Macie
C.
Amazon Inspector
Answers
C.
Amazon Inspector
D.
Amazon Security Hub
Answers
D.
Amazon Security Hub
Suggested answer: B

Explanation:

Explore

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS. It is specifically designed to support Amazon S3 storage and provides an inventory of S3 buckets, helping organizations like SecGlob Cloud Pvt. Ltd. to identify and protect their sensitive data.

Here's how Amazon Macie fulfills Martin's requirements:

1.Sensitive Data Identification: Macie automatically and continuously discovers sensitive data, such as personally identifiable information (PII), in S3 buckets.

1.Inventory and Monitoring: It provides an inventory of S3 buckets, detailing which are publicly accessible, unencrypted, or shared with accounts outside the organization.

1.Alerts and Reporting: Macie generates detailed alerts and reports when it detects unauthorized access or inadvertent data leaks.

1.Data Security Posture: It helps improve the data security posture by providing actionable recommendations for securing S3 buckets.

1.Compliance Support: Macie aids in compliance efforts by monitoring data access patterns and ensuring that sensitive data is handled according to policy.

AWS documentation on Amazon Macie, which outlines its capabilities for protecting sensitive data in S31.

An AWS blog post discussing how Macie can be used to identify and protect sensitive data in S3 buckets1.

asked 18/09/2024
Kevin Taylor
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first