Security, Identity, and Compliance
CoreAmazon Macie
Managed sensitive-data discovery and data-security findings for Amazon S3.
Key points
- Macie classifies and discovers sensitive data in S3 and reports risky data-security conditions.
- It does not replace S3 access controls, encryption, lifecycle, or general threat detection.
- Scope discovery to business need because classification consumes resources and exposes sensitive metadata to authorized operators.
Best-known use cases
- Discover personally identifiable or regulated data in S3.
- Identify S3 buckets with sensitive data and risky security posture.
What candidates often confuse it with
- Macie discovers sensitive S3 data; GuardDuty detects suspicious activity.
- Macie produces data-security findings; Security Hub aggregates findings across services.
Key takeaway
Choose Macie when the question is where sensitive data exists in S3.
Related services
- Amazon S3
- Amazon GuardDuty
- AWS Security Hub
Relevant exam tasks
- D1.2
- D1.3