AWS Certified Security – Specialty (SCS-C02) — Question 198

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring.

The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions.

Which combination of actions will meet these requirements with the LEAST operational overhead? (Choose two.)

Answer options

Correct answer: A, C

Explanation

The correct answers, A and C, ensure that Security Hub is set up efficiently across all accounts in the organization and is automatically activated for new accounts. Option B introduces unnecessary complexity by requiring a Lambda function, while D is not directly related to enabling Security Hub, and E involves manual configuration of CloudTrail which is more operationally intensive.