Q: 3
A company must inventory sensitive data across all Amazon S3 buckets in all accounts from a single
security account.
Options
Discussion
Option A works because Macie is built for S3 data discovery and lets you handle multiple accounts from a central security account. Quick check though, did the question specify if all S3 buckets are in the same org? That would impact the setup.
Annoying how they slip Security Hub in with Macie every time, but yeah, probably A.
A tbh, since Inspector can't do S3 inventory, Macie delegation is the AWS way for this use case.
I don't think D fits since Trusted Advisor can't inventory or classify S3 sensitive data like Macie can. A makes sense because delegated admin with Macie enables centralized control across accounts, which is what they're asking for. Pretty sure that's the AWS-recommended approach here, but open to other reasoning.
Be respectful. No spam.