nerdexam
Amazon

SCS-C02 · Question #212

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring. The security…

The correct answer is A. Configure a finding aggregation Region for Security Hub. Link the other Regions to the C. Turn on the option to automatically enable accounts for Security Hub. To set up AWS Security Hub for centralized security monitoring across all accounts in an AWS Organization with the least operational overhead, the best actions to take are: Solution A: Configure a finding aggregation Region for Security Hub. This allows Security Hub to…

Submitted by jakub_pl· Mar 6, 2026Security Logging and Monitoring

Question

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring. The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions. Which combination of actions will meet these requirements with the LEAST operational overhead? (Choose two.)

Options

  • AConfigure a finding aggregation Region for Security Hub. Link the other Regions to the
  • BCreate an AWS Lambda function that routes events from other Regions to the dedicated Security
  • CTurn on the option to automatically enable accounts for Security Hub.
  • DCreate an SCP that denies the securityhub DisableSecurityHub permission. Attach the SCP to
  • EConfigure services in other Regions to write events to an AWS CloudTrail organization trail.

How the community answered

(25 responses)
  • A
    76% (19)
  • B
    8% (2)
  • D
    12% (3)
  • E
    4% (1)

Explanation

To set up AWS Security Hub for centralized security monitoring across all accounts in an AWS Organization with the least operational overhead, the best actions to take are: Solution A: Configure a finding aggregation Region for Security Hub. This allows Security Hub to aggregate findings from multiple regions into a single designated region, simplifying monitoring and analysis. By centralizing findings, the security team can have a unified view of security alerts and compliance statuses across all accounts and regions, enhancing the efficiency of security Solution C: Turn on the option to automatically enable accounts for Security Hub within the AWS Organization. This ensures that as new accounts are created and added to the organization, they are automatically enrolled in Security Hub, and their findings are included in the centralized monitoring. This automation reduces the manual effort required to manage account enrollment and ensures comprehensive coverage of security monitoring across the organization. These actions collectively ensure that Security Hub is effectively configured to manage security findings across all accounts and regions, providing a comprehensive and automated approach to security monitoring with minimal manual intervention.

Topics

#Security Hub#AWS Organizations#finding aggregation#delegated administrator

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice