SOA-C03 · Question #92
A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for…
The correct answer is D. Designate an AWS Security Hub administrator account. Configure new accounts in the. AWS Security Hub natively supports running the CIS AWS Foundations Benchmark across multiple accounts in an organization. By designating a central administrator account and enabling automatic account enrollment, all current and future member accounts are automatically included…
Question
A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for Internet Security (CIS) AWS Foundations Benchmark. What is the MOST operationally efficient way to meet these requirements?
Options
- ADesignate a central security account as the AWS Security Hub administrator account. Create a
- BRun the CIS AWS Foundations Benchmark across all accounts by using Amazon Inspector.
- CDesignate a central security account as the Amazon GuardDuty administrator account. Create a
- DDesignate an AWS Security Hub administrator account. Configure new accounts in the
How the community answered
(27 responses)- A4% (1)
- B11% (3)
- C4% (1)
- D81% (22)
Explanation
AWS Security Hub natively supports running the CIS AWS Foundations Benchmark across multiple accounts in an organization. By designating a central administrator account and enabling automatic account enrollment, all current and future member accounts are automatically included in Security Hub compliance checks. This approach eliminates the need for manual scripting or account invitations, providing the most operationally efficient and scalable solution.
Topics
Community Discussion
No community discussion yet for this question.