Skip to main content
Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console. Open IP Lab Portal

Overview

Prerequisites

  1. Good knowledge of AWS Service
    • Amazon Macie
    • S3 Bucket
  2. Laptop/Desktop
  3. Internet Browser
  4. Internet connection

Challenge Instructions

  1. Region: Make sure to use us-east-1 region to create all the resources.
  2. You will be provided with the requirements of the challenge. If you are new to AWS Cloud, we recommend you go through our hands-on labs before taking this challenge.
  3. Challenge Duration: 60 minutes

How to submit the challenge

  1. After building the infrastructure, click on the Validation button, to validate if you have built the required infrastructure and completed the challenge successfully.
  2. Validation status:
    • Success - you have completed the challenge successfully.
    • Failed - you have failed to complete the challenge.
  3. Once you have successfully validated the challenge, click on End Lab button to end the challenge.

Launching Challenge Environment

  1. To launch the challenge environment, click on the Start Challenge button.
  2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
  3. Once the challenge is started, you will be provided with IAM Username, Password, Access Key, and Secret Access Key.

Lab guide

Sign in to AWS Management Console

  1. Click on the Open Console button, and you will get redirected to AWS console in a new browser tab.
  2. On the AWS sign-in page, leave the account id as default. Never edit/remove the 12-digit account id present in the AWS console. Otherwise, you cannot proceed with the challenge.
  3. Now copy your Username and Password in the lab console to the IAM username and password in AWS console and click on the sign in button.
  4. Once signed in to the AWS management console, make the default AWS region as US East (N. Virginia) us-east-1.

Cloud Challenge Details

In this challenge lab, your AWS management and governance skills are put to the test as you embark on creating and configuring an Amazon Macie job to uncover sensitive data.

Architecture Diagram

As an AWS Cloud Architect at XYZ Company, you’ve been entrusted with enhancing data security measures to tackle growing concerns surrounding data privacy and regulatory compliance within the financial sector. To address these challenges, you recommended implementing Amazon Macie. This sophisticated AI-powered service is purpose-built to discover, classify, and safeguard sensitive data stored in Amazon S3.
  1. Enable AWS Macie for the account.
  2. Create a Macie job according to the provided instructions:
    • Start by selecting the S3 bucket whose name starts with “whizlabs”.
    • Refine the scope for sensitive data discovery:
      • Sensitive data discovery: One-time job
      • Object criteria: File name extensions.
      • Include: File name extensions: csv
    • Select managed data identifiers: Recommended
    • For Custom data identifiers, create a Managed custom identifier:
      • Name: Whiz
      • Regular expression: [a-z]{2}-[0-9]{2}
    • Select allow lists.
    • For general settings, provide:
      • Job name: WhizJob
  3. Wait for Macie job completion, then view findings, and export them as a JSON report.

End Challenge

  1. Sign Out of the AWS account.
  2. You have successfully completed the challenge.
  3. Click on End Challenge button from IP Lab Portal Labs console and wait till the process gets completed.

What gets checked

When you press Check my work, the platform verifies each of these:
  • Check Macie job findings — Check whether Macie job findings are present or not
  • Create a Macie Classification job — Check whether a Macie classification job is created or not