Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Exhibit

Security review notes:

- S3 bucket contains employee records, exports, and uploaded documents
- Team wants to find objects that contain personally identifiable information
- A sample report shows files with patterns resembling SSNs and bank account numbers
- The team needs ongoing classification findings, not just API activity logs

Based on the exhibit, which AWS service should the security team enable to continuously discover sensitive data stored inside Amazon S3 objects?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Macie with Amazon GuardDuty, mistakenly thinking GuardDuty's threat detection includes scanning for sensitive data, when in fact GuardDuty focuses on security threats and anomalies, not data classification or content inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Macie

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as personally identifiable information (PII) or financial data stored in Amazon S3. It provides continuous visibility into data security risks by generating findings when sensitive data is detected, making it the correct choice for this use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity across your AWS account, capturing who made which S3 API calls (GetObject, PutObject, ListBucket) from what source IP and when. It is an audit trail for operational and security investigations, enabling answers to questions like 'who accessed this bucket?' However, CloudTrail does not inspect the object payload itself; the data content inside S3 objects is never part of the CloudTrail event record, so it cannot classify the object as containing sensitive personal information.

    When this WOULD be correct

    A security team needs to audit all API calls made to S3 buckets, including who accessed objects and when, to meet compliance requirements. CloudTrail would be the correct service to enable for tracking S3 API activity.

  • ✓

    Amazon Macie

    Why this is correct

    Macie is the AWS service designed to discover and classify sensitive data in S3. It can continuously analyze buckets for personal data patterns and produce findings when sensitive information is detected. That matches the requirement for ongoing classification of object contents rather than audit logs or configuration checks.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration auditing and compliance service that continuously evaluates your AWS resource configurations against desired policies, such as checking whether an S3 bucket is publicly accessible, has versioning enabled, or has default encryption. It records configuration item changes and can trigger remediation, but its scope is resource settings and metadata, not the data stored within the objects. AWS Config has no mechanism to read or analyze the actual content of S3 files, so it cannot identify personal data or classify the sensitivity of the data itself.

    When this WOULD be correct

    A security team needs to continuously monitor and record changes to S3 bucket policies, ACLs, and other resource configurations to ensure compliance with internal security standards. AWS Config would be the correct service to track configuration changes and evaluate rules against desired configurations.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that consumes AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs to identify malicious activity or unauthorized behavior. It uses anomaly detection and threat intelligence feeds to flag things like crypto mining, credential compromise, or outbound data exfiltration attempts. Critically, GuardDuty never reads the byte-level contents of S3 objects; it evaluates metadata and network telemetry, so it cannot determine whether a file contains PII or classified personal data.

    When this WOULD be correct

    GuardDuty would be correct if the question asked for a service that continuously monitors for suspicious API calls or potential security threats (e.g., compromised credentials, unusual data access patterns) across AWS accounts and workloads, including S3 access patterns.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Amazon MacieCorrect answer▾

Why this is correct

Macie is the AWS service designed to discover and classify sensitive data in S3. It can continuously analyze buckets for personal data patterns and produce findings when sensitive information is detected. That matches the requirement for ongoing classification of object contents rather than audit logs or configuration checks.

✗AWS CloudTrailWrong answer — click to see why▾

Why this is wrong here

AWS CloudTrail records API activity for auditing, not for discovering sensitive data within S3 objects. It cannot inspect object contents for sensitive information like PII or financial data.

★ When this WOULD be the correct answer

A security team needs to audit all API calls made to S3 buckets, including who accessed objects and when, to meet compliance requirements. CloudTrail would be the correct service to enable for tracking S3 API activity.

Why candidates choose this

Candidates may confuse CloudTrail's logging of S3 operations with data discovery, assuming that logging all actions includes scanning object contents, which it does not.

✗AWS ConfigWrong answer — click to see why▾

Why this is wrong here

AWS Config is designed to evaluate and monitor resource configurations and compliance, not to discover or classify sensitive data within S3 objects. It cannot inspect the content of objects for sensitive information like PII or financial data.

★ When this WOULD be the correct answer

A security team needs to continuously monitor and record changes to S3 bucket policies, ACLs, and other resource configurations to ensure compliance with internal security standards. AWS Config would be the correct service to track configuration changes and evaluate rules against desired configurations.

Why candidates choose this

Candidates may confuse AWS Config's ability to monitor S3 bucket configurations with the capability to inspect object content, assuming that 'monitoring' includes data discovery, or they may think Config can scan objects for compliance rules.

✗Amazon GuardDutyWrong answer — click to see why▾

Why this is wrong here

Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for discovering sensitive data within S3 objects. It does not perform content inspection or classification of data stored in S3.

★ When this WOULD be the correct answer

GuardDuty would be correct if the question asked for a service that continuously monitors for suspicious API calls or potential security threats (e.g., compromised credentials, unusual data access patterns) across AWS accounts and workloads, including S3 access patterns.

Why candidates choose this

Candidates may confuse GuardDuty's threat detection capabilities with data discovery, assuming it can identify sensitive data as part of its monitoring, or they may think it scans S3 objects for anomalies that could indicate sensitive data exposure.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.