AWS Certified SysOps Administrator – Associate (SOA-C03) — Question 16

A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for Internet Security (CIS) AWS Foundations Benchmark.
What is the MOST operationally efficient way to meet these requirements?

Answer options

Correct answer: D

Explanation

The correct answer is D because it allows for automatic integration of new accounts into the AWS Security Hub, simplifying the management of CIS AWS Foundations Benchmark scans. Option A requires manual scripting for each new account, which is less efficient. Option B uses Amazon Inspector, which is not specifically designed for this benchmark scanning task. Option C involves GuardDuty, which does not perform the CIS AWS Foundations Benchmark scans as intended.