A company uses an AWS Organizations organization with all features enabled and provisions new accounts through AWS Control Tower Account Factory. Trusted access for AWS Account Management is enabled. The company must ensure all new accounts in the organization are enrolled as AWS Security Hub member accounts. Which solution requires the least development effort?
Choose an answer
Tap an option to check your answer.
Correct answer: From the organization’s management account, designate a Security Hub delegated administrator. In the delegated administrator account, create a configuration policy to enable Security Hub and associate it with the organization root..
Why this is the answer
The correct solution leverages AWS Security Hub's integration with AWS Organizations. By designating a delegated administrator, that account can centrally manage Security Hub for the entire organization. Creating a configuration policy within the delegated administrator account to enable Security Hub and associating it with the organization root ensures that all existing and future accounts automatically become Security Hub member accounts. This is the most integrated and automated approach, requiring minimal custom development. The other options involve more manual or custom development efforts: Enabling Security Hub in the management account alone does not automatically enroll all member accounts. Step Functions or Lambda solutions require custom code development and maintenance, which is more effort than using native Security Hub organization features.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed