Prepare a PHI/public-bucket audit with Macie, Audit Manager, and Security Hub FSBP
A medical company recently completed an acquisition and inherited an existing AWS environment. The company has an upcoming audit and is concerned about the compliance posture of its acquisition. The company must identify personal health information inside Amazon S3 buckets and must identify S3 buckets that are publicly accessible. The company needs to prepare for the audit by collecting evidence in the environment. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose three.)
Community Votes
100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Macie is the managed service for discovering PII/PHI in S3 via managed data identifiers. Audit Manager is built to collect and structure compliance evidence for audits. Security Hub FSBP includes S3 public-access controls, giving centralized evidence of publicly accessible buckets. Glue (B) masks data rather than discovering it for audit, and GuardDuty S3 Protection (D) detects suspicious access, not PHI identification or public-bucket posture.
Before an audit, the company must find PHI in S3, find publicly accessible buckets, and collect compliance evidence with least overhead. Amazon Macie with the PERSONAL_INFORMATION managed data identifier discovers PHI in S3; AWS Audit Manager creates an assessment under a supported framework and assembles audit-ready evidence; AWS Security Hub's AWS Foundational Security Best Practices standard reports controls like S3 Block Public Access, evidencing public-bucket posture. Together they cover all three needs natively.
Using AWS Glue Detect PII (option B), which transforms/masks data instead of discovering it for audit evidence, or GuardDuty S3 Protection (option D), which detects anomalous access rather than identifying PHI or public buckets.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.