Courseiva
Data ProtectionhardMultiple ChoiceObjective-mapped

SCS-C03 Data Protection Practice Question

A security engineer needs to identify and protect Personally Identifiable Information (PII) stored in thousands of S3 buckets across multiple AWS accounts. The solution must provide a centralized dashboard and use machine learning to classify data. Which service is best suited for this task?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon Macie

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in Amazon S3. Macie automatically provides an inventory of S3 buckets and can be configured to scan objects for PII, providing a centralized view of data risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon Macie

    Why this is correct

    Amazon Macie is specifically designed for S3 data discovery and classification. It uses machine learning to identify sensitive data like credit card numbers or names. Macie integrates with AWS Organizations, allowing a security hub account to manage discovery jobs across thousands of buckets and accounts from a single centralized dashboard.

  • Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. While it has a feature to monitor S3 data access events (S3 Protection), it does not scan the actual content of the files to classify PII or provide a data inventory. Macie is the correct tool for data classification.

  • AWS Glue DataBrew

    Why it's wrong here

    AWS Glue DataBrew is a visual data preparation tool for cleaning and normalizing data for analytics. While it can identify data types, it is not a security service designed for multi-account PII discovery and protection. It lacks the automated scanning and centralized security reporting features that are foundational to Amazon Macie.

  • AWS Security Hub

    Why it's wrong here

    Security Hub provides a comprehensive view of your security alerts and posture across AWS accounts. While it can ingest findings from Amazon Macie, it does not perform the data discovery itself. It acts as an aggregator for findings rather than the primary engine for scanning S3 objects for sensitive PII.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.