AWS Certified Security – Specialty — Question 254

A security engineer has enabled AWS Security Hub in their AWS account, and has enabled the Center for Internet Security (CIS) AWS Foundations compliance standard. No evaluation results on compliance are returned in the Security Hub console after several hours. The engineer wants to ensure that Security Hub can evaluate their resources for CIS AWS Foundations compliance.
Which steps should the security engineer take to meet these requirements?

Answer options

Correct answer: C

Explanation

The correct answer is C because AWS Config must be enabled along with the specific AWS Config rules to properly evaluate resources for CIS compliance. Options A and B are incorrect as they pertain to unrelated services that do not directly influence the CIS compliance evaluation. Option D is also incorrect since CloudTrail monitoring is not a requirement for CIS compliance evaluation in Security Hub.