Macie Flashcards

This deck aims to help retain concepts related to the AWS Macie service. (14 cards)

1
Q

What fully managed AWS data security service uses machine learning and pattern matching to discover, classify, and protect sensitive data stored in Amazon S3?

A

Amazon Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary function of Amazon Macie?

A
  • Discover, monitor, and protect sensitive data in S3
  • Automated detection of Personally Identifiable Information (PII), Protected Health Information (PHI), and financial data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Amazon Macie use to determine how S3 objects and their content are evaluated?

A

Data identifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What types of data identifiers does Amazon Macie provide?

A
  • Managed data identifiers
  • Custom data identifiers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Amazon Macie data identifiers use built-in techniques such as machine learning and pattern matching?

A

Managed data identifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which Amazon Macie data identifiers are customer-defined, regex-based, and proprietary?

A

Custom data identifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What Amazon Macie component uses data identifiers to scan S3 buckets for sensitive data?

A

Discovery job

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is generated when an Amazon Macie discovery job finds matches?

A

Findings are produced and can be viewed, or forwarded to Security Hub or EventBridge for automated remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does Amazon Macie support native multi-account integration?

A

Yes, through a multi-account architecture where an administrator account manages member accounts using AWS Organizations or Macie account invitations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What types of findings can Amazon Macie generate when a discovery job detects matches?

A
  • Policy findings
  • Sensitive data findings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Amazon Macie findings are generated when bucket policies or settings reduce the security of a bucket or its objects?

A

Policy findings (only after Macie is enabled)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Provide an example of an Amazon Macie policy finding.

A
  • Policy:IAMUser/S3BlockPublicAccessDisabled
  • Policy:IAMUser/S3BucketEncryptionDisabled
  • Policy:IAMUser/S3BucketPublic
  • Policy:IAMUser/S3BucketSharedExternally
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which Amazon Macie findings provide details about sensitive data detected in S3 objects?

A

Sensitive data findings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Provide an example of an Amazon Macie sensitive data finding.

A
  • SensitiveData:S3Object/Credentials
  • SensitiveData:S3Object/CustomIdentifier
  • SensitiveData:S3Object/Financial
  • SensitiveData:S3Object/Multiple
  • SensitiveData:S3Object/Personal
How well did you know this?
1
Not at all
2
3
4
5
Perfectly