Security, Identity, and Compliance
CoreAmazon Macie
Sensitive-data and PII discovery for Amazon S3.
Key points
- Macie discovers and classifies sensitive data, including personally identifiable information, in S3.
- A finding identifies potential exposure; remediation still depends on S3, IAM, and lake-governance controls.
Best-known use cases
- Discover sensitive data and personally identifiable information in S3.
- Prioritize remediation for exposed or improperly governed data-lake objects.
What candidates often confuse it with
- Macie detects sensitive S3 data; Lake Formation or access policies enforce who may use governed data.
Key takeaway
Choose Macie to locate sensitive S3 objects and prioritize governance remediation.
Relevant exam tasks
- D4.5 — Task 4.5: Understand data privacy and governance
- 4.5.2 — Implement PII identification (for example, Amazon Macie with Lake Formation).