nerdexam
Amazon

SCS-C02 · Question #214

A company used AWS Organizations to set up an environment with multiple AWS accounts. The company's organization currently has two AWS accounts, and the company expects to add more than 50 AWS…

The correct answer is B. Create a new AWS account in the organization. Enable GuardDuty in the new account. Designate. For a company using AWS Organizations that requires centralized management and automatic activation of Amazon GuardDuty across all current and future AWS accounts, setting up a delegated administrator account for GuardDuty is the optimal solution. By enabling GuardDuty in a new…

Submitted by haru.x· Mar 6, 2026Threat Detection and Incident Response

Question

A company used AWS Organizations to set up an environment with multiple AWS accounts. The company's organization currently has two AWS accounts, and the company expects to add more than 50 AWS accounts during the next 12 months The company will require all existing and future AWS accounts to use Amazon GuardDuty. Each existing AWS account has GuardDuty active. The company reviews GuardDuty findings by logging into each AWS account individually. The company wants a centralized view of the GuardDuty findings for the existing AWS accounts and any future AWS accounts. The company also must ensure that any new AWS account has GuardDuty automatically turned on. Which solution will meet these requirements?

Options

  • AEnable AWS Security Hub in the organization's management account. Configure GuardDuty
  • BCreate a new AWS account in the organization. Enable GuardDuty in the new account. Designate
  • CCreate a new AWS account in the organization. Enable GuardDuty in the new account. Enable
  • DEnable AWS Security Hub in the organization's management account. Designate the

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    75% (18)
  • C
    13% (3)
  • D
    8% (2)

Explanation

For a company using AWS Organizations that requires centralized management and automatic activation of Amazon GuardDuty across all current and future AWS accounts, setting up a delegated administrator account for GuardDuty is the optimal solution. By enabling GuardDuty in a new account and designating it as the delegated administrator, the company can centrally manage GuardDuty findings and automatically enroll new AWS accounts into GuardDuty as they are created within the organization. This approach ensures consistent threat detection and continuous monitoring across all accounts, aligning with best security practices.

Topics

#GuardDuty#AWS Organizations#centralized findings#delegated administrator

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice