Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A company is implementing a data loss prevention (DLP) solution for data stored in Amazon S3. The data includes personally identifiable information (PII). The company wants to automatically identify and classify PII objects, then apply encryption using AWS KMS with a customer-managed key. Which AWS service should be used to identify PII?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Macie

Amazon Macie is the correct service because it uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII in Amazon S3. AWS CloudTrail (Option A) logs API calls and does not inspect data content. Amazon GuardDuty (Option C) detects threats and unauthorized behavior, not data classification. AWS Config (Option D) evaluates resource configurations and compliance, not data content. Therefore, Option B is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records account activity across AWS services as API call logs, capturing who made a request, the source IP, and the affected resource, but it does not inspect or retain the contents of S3 object payloads. Since DLP requires examining data at rest or in transit for sensitive content, CloudTrail cannot identify PII such as names, addresses, or credit card numbers stored in files. It could support an audit trail of who interacted with a DLP solution, but it is not a data-content scanning service.

  • ✓

    Amazon Macie

    Why this is correct

    Amazon Macie is a fully managed data security and privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data in Amazon S3, including PII, PHI, and financial information. It supports DLP by generating custom findings and sending alerts via Amazon EventBridge or AWS Security Hub, and it can integrate with AWS Organizations to scale across multiple accounts. Macie provides both managed data identifiers and custom identifiers so customers can detect proprietary or regulatory data types.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes continuously streaming metadata from AWS CloudTrail Events, VPC Flow Logs, and DNS Logs to identify anomalous behavior such as brute-force attacks, cryptojacking, or unauthorized activity. It does not open and inspect S3 object content, so it cannot report whether a specific file contains social security numbers or other PII. GuardDuty may alert on suspicious access patterns to S3, but classification of sensitive data requires a purpose-built data discovery tool like Macie.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is focused on continuous monitoring and recording of changes to AWS resource configurations, such as bucket policies, encryption settings, and lifecycle rules, enabling compliance auditing and configuration drift detection. It does not scan the data inside objects, so it cannot determine whether a document contains PII or whether sensitive data is located in a specific S3 prefix. AWS Config can be used in a DLP strategy to enforce and validate technical controls like S3 Block Public Access, but it is not a content-aware data scanning service.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.