nerdexam
Amazon

SOA-C03 · Question #92

A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for…

The correct answer is D. Designate an AWS Security Hub administrator account. Configure new accounts in the. AWS Security Hub natively supports running the CIS AWS Foundations Benchmark across multiple accounts in an organization. By designating a central administrator account and enabling automatic account enrollment, all current and future member accounts are automatically included…

Submitted by paula_co· Mar 5, 2026Security and compliance

Question

A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for Internet Security (CIS) AWS Foundations Benchmark. What is the MOST operationally efficient way to meet these requirements?

Options

  • ADesignate a central security account as the AWS Security Hub administrator account. Create a
  • BRun the CIS AWS Foundations Benchmark across all accounts by using Amazon Inspector.
  • CDesignate a central security account as the Amazon GuardDuty administrator account. Create a
  • DDesignate an AWS Security Hub administrator account. Configure new accounts in the

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    4% (1)
  • D
    81% (22)

Explanation

AWS Security Hub natively supports running the CIS AWS Foundations Benchmark across multiple accounts in an organization. By designating a central administrator account and enabling automatic account enrollment, all current and future member accounts are automatically included in Security Hub compliance checks. This approach eliminates the need for manual scripting or account invitations, providing the most operationally efficient and scalable solution.

Topics

#Security Hub#CIS Benchmark#Organizations#compliance scanning

Community Discussion

No community discussion yet for this question.

Full SOA-C03 Practice