AWS Certified SysOps Administrator – Associate — Question 192

A company manages a set of accounts on AWS by using AWS Organizations. The company's security team wants to use a native AWS service to regularly scan all AWS accounts against the Center for Internet Security (CIS) AWS Foundations Benchmark.

What is the MOST operationally efficient way to meet these requirements?

Answer options

Correct answer: D

Explanation

The correct answer is D because it allows for automatic membership and scanning of new accounts without the need for manual intervention, making it the most operationally efficient solution. Options A and C require additional manual scripting every time a new account is created, which is less efficient. Option B does not utilize the native service specifically designed for this purpose, which is AWS Security Hub.