SCS-C02 Data Protection Practice Question
A company is implementing a data loss prevention (DLP) solution for data stored in Amazon S3. The data includes personally identifiable information (PII). The company wants to automatically identify and classify PII objects, then apply encryption using AWS KMS with a customer-managed key. Which AWS service should be used to identify PII?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Macie
Amazon Macie is the correct service because it uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII in Amazon S3. AWS CloudTrail (Option A) logs API calls and does not inspect data content. Amazon GuardDuty (Option C) detects threats and unauthorized behavior, not data classification. AWS Config (Option D) evaluates resource configurations and compliance, not data content. Therefore, Option B is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records account activity across AWS services as API call logs, capturing who made a request, the source IP, and the affected resource, but it does not inspect or retain the contents of S3 object payloads. Since DLP requires examining data at rest or in transit for sensitive content, CloudTrail cannot identify PII such as names, addresses, or credit card numbers stored in files. It could support an audit trail of who interacted with a DLP solution, but it is not a data-content scanning service.
- ✓
Amazon Macie
Why this is correct
Amazon Macie is a fully managed data security and privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data in Amazon S3, including PII, PHI, and financial information. It supports DLP by generating custom findings and sending alerts via Amazon EventBridge or AWS Security Hub, and it can integrate with AWS Organizations to scale across multiple accounts. Macie provides both managed data identifiers and custom identifiers so customers can detect proprietary or regulatory data types.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that analyzes continuously streaming metadata from AWS CloudTrail Events, VPC Flow Logs, and DNS Logs to identify anomalous behavior such as brute-force attacks, cryptojacking, or unauthorized activity. It does not open and inspect S3 object content, so it cannot report whether a specific file contains social security numbers or other PII. GuardDuty may alert on suspicious access patterns to S3, but classification of sensitive data requires a purpose-built data discovery tool like Macie.
- ✗
AWS Config
Why it's wrong here
AWS Config is focused on continuous monitoring and recording of changes to AWS resource configurations, such as bucket policies, encryption settings, and lifecycle rules, enabling compliance auditing and configuration drift detection. It does not scan the data inside objects, so it cannot determine whether a document contains PII or whether sensitive data is located in a specific S3 prefix. AWS Config can be used in a DLP strategy to enforce and validate technical controls like S3 Block Public Access, but it is not a content-aware data scanning service.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.