SAA-C03 · Question #541
A company needs to create a compliance management solution. The company wants to use a combination of AWS services to achieve the fine-grained visibility that the solution requires. The compliance man
The correct answer is C. Configure AWS Security Hub to centralize findings. Use conformance packs in AWS Config to. AWS Security Hub provides a centralized view of security findings across AWS accounts and services. It integrates natively with AWS Config conformance packs, which evaluate compliance against industry standards such as CIS and PCI-DSS. "AWS Security Hub aggregates, organizes, and
Question
A company needs to create a compliance management solution. The company wants to use a combination of AWS services to achieve the fine-grained visibility that the solution requires. The compliance management solution must provide a centralized method for company employees to review security findings and out-of-compliance findings. Which solution will meet these requirements with the LEAST ongoing maintenance?
Options
- AConfigure AWS Security Hub to centralize findings. Use conformance packs in Amazon Inspector
- BUse AWS Marketplace to purchase a security tool. Install the tool on an Amazon EC2 instance.
- CConfigure AWS Security Hub to centralize findings. Use conformance packs in AWS Config to
- DConfigure AWS Systems Manager to provide a centralized dashboard. Use conformance packs in
How the community answered
(36 responses)- A6% (2)
- B3% (1)
- C81% (29)
- D11% (4)
Explanation
AWS Security Hub provides a centralized view of security findings across AWS accounts and services. It integrates natively with AWS Config conformance packs, which evaluate compliance against industry standards such as CIS and PCI-DSS. "AWS Security Hub aggregates, organizes, and prioritizes security alerts and compliance status across AWS accounts. Use AWS Config conformance packs to assess compliance with security Why C is correct: Security Hub provides a centralized dashboard for compliance visibility. Conformance packs in AWS Config automate compliance checks across accounts. Fully managed, minimal maintenance, and integrates natively with AWS services. Why others are incorrect: A: Conformance packs are not a feature of Amazon Inspector. B: Third-party tools on EC2 require management and add operational overhead. D: Systems Manager is not designed for compliance aggregation.
Community Discussion
No community discussion yet for this question.