Lab 1 · Discover & Classify Sensitive Data
Find sensitive data across S3 and databases — and catch a bucket whose name doesn't match its contents.
Scenario tie-in
Some data is genuinely sensitive; some is decoy. Trust the classifier, not the label.
1.1 IaaS dashboard
- Dashboards → IaaS, filter on AWS.
- Read the Key Risk Indicators bar.
- Scan the sensitive-data widgets.
1.2 Tree View
- Data Stores Tree View → expand Account → S3; note sensitive buckets.
- Expand RDS: classification category per table/column.
1.3 Catch the mislabeled bucket
- One named for cardholder data — classification shows non-sensitive (decoy).
- One bland name — actually real patient records (PHI + PII).
Done when
You can point to real sensitive-data locations from DAC evidence and spotted the label mismatch.

