SCS-C03 Data Protection Practice Question
A security engineer needs to identify and protect Personally Identifiable Information (PII) stored in thousands of S3 buckets across multiple AWS accounts. The solution must provide a centralized dashboard and use machine learning to classify data. Which service is best suited for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Macie
Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in Amazon S3. Macie automatically provides an inventory of S3 buckets and can be configured to scan objects for PII, providing a centralized view of data risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon Macie
Why this is correct
Amazon Macie is specifically designed for S3 data discovery and classification. It uses machine learning to identify sensitive data like credit card numbers or names. Macie integrates with AWS Organizations, allowing a security hub account to manage discovery jobs across thousands of buckets and accounts from a single centralized dashboard.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. While it has a feature to monitor S3 data access events (S3 Protection), it does not scan the actual content of the files to classify PII or provide a data inventory. Macie is the correct tool for data classification.
- ✗
AWS Glue DataBrew
Why it's wrong here
AWS Glue DataBrew is a visual data preparation tool for cleaning and normalizing data for analytics. While it can identify data types, it is not a security service designed for multi-account PII discovery and protection. It lacks the automated scanning and centralized security reporting features that are foundational to Amazon Macie.
- ✗
AWS Security Hub
Why it's wrong here
Security Hub provides a comprehensive view of your security alerts and posture across AWS accounts. While it can ingest findings from Amazon Macie, it does not perform the data discovery itself. It acts as an aggregator for findings rather than the primary engine for scanning S3 objects for sensitive PII.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.