nerdexam
Amazon

DOP-C02 · Question #116

A company recently created a new AWS Control Tower landing zone in a new organization in AWS Organizations. The landing zone must be able to demonstrate compliance with the Center for Internet Securit

The correct answer is A. Turn on trusted access for Security Hub in the organization's management account. Create a new C. Create an AWS IAM Identity Center (AWS Single Sign-On) permission set that includes the required E. In Security Hub, turn on automatic enablement.. https://docs.aws.amazon.com/securityhub/latest/userguide/accounts-orgs-auto-enable.html

Submitted by valeria.br· Mar 6, 2026Security and Compliance

Question

A company recently created a new AWS Control Tower landing zone in a new organization in AWS Organizations. The landing zone must be able to demonstrate compliance with the Center for Internet Security (CIS) Benchmarks for AWS Foundations. The company's security team wants to use AWS Security Hub to view compliance across all accounts. Only the security team can be allowed to view aggregated Security Hub findings. In addition, specific users must be able to view findings from their own accounts within the organization. All accounts must be enrolled in Security Hub after the accounts are created. Which combination of steps will meet these requirements in the MOST automated way? (Choose three.)

Options

  • ATurn on trusted access for Security Hub in the organization's management account. Create a new
  • BTurn on trusted access for Security Hub in the organization's management account. From the
  • CCreate an AWS IAM Identity Center (AWS Single Sign-On) permission set that includes the required
  • DCreate an SCP that explicitly denies any user who is not on the security team from accessing Security
  • EIn Security Hub, turn on automatic enablement.
  • FIn the organization's management account, create an Amazon EventBridge rule that reacts to the

How the community answered

(25 responses)
  • A
    64% (16)
  • B
    20% (5)
  • D
    12% (3)
  • F
    4% (1)

Explanation

https://docs.aws.amazon.com/securityhub/latest/userguide/accounts-orgs-auto-enable.html

Topics

#Security Hub#AWS Organizations#Compliance#IAM Identity Center

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice