Prepare a PHI/public-bucket audit with Macie, Audit Manager, and Security Hub FSBP

Answer Correct answer: A, C, E — Macie discovers PHI, Audit Manager collects audit evidence, and Security Hub FSBP evidences public S3 buckets.

A medical company recently completed an acquisition and inherited an existing AWS environment. The company has an upcoming audit and is concerned about the compliance posture of its acquisition. The company must identify personal health information inside Amazon S3 buckets and must identify S3 buckets that are publicly accessible. The company needs to prepare for the audit by collecting evidence in the environment. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose three.)

  1. Enable Amazon Macie. Run an on-demand sensitive data discovery job that uses the PERSONAL_INFORMATION managed data identifier. Correct Answer
  2. Use AWS Glue with the Detect PII transform to identify sensitive data and to mask the sensitive data.
  3. Enable AWS Audit Manager. Create an assessment by using a supported framework. Correct Answer
  4. Enable Amazon GuardDuty S3 Protection. Document any findings that are related to suspicious access of S3 buckets.
  5. Enable AWS Security Hub. Use the AWS Foundational Security Best Practices standard. Review the controls dashboard for evidence of failed S3 Block Public Access controls. Correct Answer

Community Votes

ACE
100%

100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Macie is the managed service for discovering PII/PHI in S3 via managed data identifiers. Audit Manager is built to collect and structure compliance evidence for audits. Security Hub FSBP includes S3 public-access controls, giving centralized evidence of publicly accessible buckets. Glue (B) masks data rather than discovering it for audit, and GuardDuty S3 Protection (D) detects suspicious access, not PHI identification or public-bucket posture.

Before an audit, the company must find PHI in S3, find publicly accessible buckets, and collect compliance evidence with least overhead. Amazon Macie with the PERSONAL_INFORMATION managed data identifier discovers PHI in S3; AWS Audit Manager creates an assessment under a supported framework and assembles audit-ready evidence; AWS Security Hub's AWS Foundational Security Best Practices standard reports controls like S3 Block Public Access, evidencing public-bucket posture. Together they cover all three needs natively.

Using AWS Glue Detect PII (option B), which transforms/masks data instead of discovering it for audit evidence, or GuardDuty S3 Protection (option D), which detects anomalous access rather than identifying PHI or public buckets.

Community Discussion (7 comments)

phmeeeee 👍 1 Selected: ACE
ACE is the combination. F - is covered by SecurityHub.
AWSLoverLoverLoverLoverLover 👍 1 Selected: AE
Amazon Macie is a service specifically designed to discover and classify sensitive data, such as personal health information (PHI), inside S3 buckets. Using the PERSONAL_INFORMATION managed data identifier enables the discovery of personal data (PII/PHI) within S3 buckets. AWS Security Hub provides a centralized view of security alerts and compliance status. Enabling the AWS Foundational Security Best Practices standard helps identify and evaluate controls like S3 Block Public Access settings, which would show any violations, helping to identify publicly accessible S3 buckets. The s3-bucket-public-write-prohibited rule in AWS Config helps enforce compliance by ensuring that S3 buckets are not publicly writable. This is a key aspect of ensuring that sensitive data is not inadvertently exposed, and it helps identify any S3 buckets that might be misconfigured.
Pat9595 👍 1 Selected: AC
The audit readiness requirement leans toward AWS Audit Manager (C) since it is explicitly designed to collect and organize evidence for compliance audits. While Security Hub (E) provides excellent security monitoring, Audit Manager (C) is more suited for preparing for an audit and collecting structured compliance evidence.
Wardove 👍 2 Selected: ACE
F cannot be the right answer as mentioned control would capture public reads from non-compliant resources https://docs.aws.amazon.com/config/latest/developerguide/s3-bucket-public-write-prohibited.html
IPLogic 👍 4 Selected: ACE
A. Amazon Macie specializes in discovering sensitive data, such as personal health information, within your S3 buckets. This directly addresses the need to identify such data. C. AWS Audit Manager helps you create assessments and gather evidence based on compliance frameworks, preparing you thoroughly for the audit. E. AWS Security Hub provides a consolidated view of your security posture and identifies public access issues for S3 buckets, helping you review and document compliance with best practices.
HappyG 👍 2 Selected: AE
The combination of A (Macie for PHI detection), E (Security Hub for centralized compliance monitoring), and F (AWS Config for continuous bucket access monitoring) provides an efficient and low-overhead solution to meet the requirements. It doesn't ask for anything from Audit, it's a distraction answer.
debarshi 👍 4 Selected: AC
Correct Answer: ACF

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A (Macie) identifies PHI in S3 using the PERSONAL_INFORMATION managed data identifier. C (Audit Manager) builds an assessment from a supported framework and continuously gathers audit-ready evidence. E (Security Hub FSBP) evaluates S3 Block Public Access and related controls, surfacing publicly accessible buckets as evidence. The three together meet PHI discovery, public-bucket identification, and audit-evidence collection with minimal operational effort.

Why the Other Options Are Wrong

B (Glue Detect PII) is a data-transform/masking step, not a discovery-and-evidence tool for the audit. D (GuardDuty S3 Protection) flags suspicious S3 access activity, not PHI content or public-bucket configuration. Neither substitutes for Macie's PHI discovery or Security Hub's public-access control evidence.

Community Comment Notes

Community favored A,C,E (47 votes). Commenters noted Macie finds PHI, Audit Manager assembles audit evidence, and Security Hub FSBP evidences public-access controls; some suggested an AWS Config option, but Config is covered by Security Hub FSBP. A minority mistakenly included a non-listed option, but the valid trio is A,C,E.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide