A company uses AWS Organizations and needs to centralize AWS Security Hub in a dedicated account to monitor all existing and future accounts across all AWS Regions with minimal operations effort. Which combination of actions meets these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure a Security Hub finding aggregation Region and link all other Regions to it., Enable the Security Hub setting to automatically enable new and existing organization accounts..
Why this is the answer
To centralize Security Hub across an AWS Organization with minimal operational effort, you need to enable Security Hub for all accounts and aggregate findings. Enabling the Security Hub setting to automatically enable new and existing organization accounts ensures that Security Hub is turned on for all current and future member accounts, simplifying management. Configuring a Security Hub finding aggregation Region and linking all other Regions to it centralizes all Security Hub findings into a single Region within the delegated administrator account, allowing for a consolidated view of security posture across the entire organization and all Regions. Incorrect options: Creating a Lambda function to route events is unnecessary and adds operational overhead; Security Hub's native aggregation features handle this. Creating an SCP to deny securityhub:DisableSecurityHub is a good security practice but does not enable Security Hub or aggregate findings, which are the core requirements. Configuring services to write to an AWS CloudTrail organization trail and having Security Hub read from it is not how Security Hub collects findings; Security Hub processes its own data sources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed