A company uses AWS Organizations and plans to grow from 2 to more than 50 AWS accounts over the next year. GuardDuty is already enabled in existing accounts. The company wants a centralized view of GuardDuty findings for all current and future accounts and needs GuardDuty to be automatically enabled for any new account. What should the company do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new account in the organization. Enable GuardDuty in that account and designate it as the GuardDuty delegated administrator. Add existing accounts as member accounts and enable automatic enrollment for new organization accounts..
Why this is the answer
The correct solution leverages GuardDuty's delegated administrator feature within AWS Organizations. By designating a dedicated account as the GuardDuty delegated administrator, the company gains a centralized view of findings across all member accounts. The administrator account can also automatically enable GuardDuty for any new accounts added to the organization, ensuring comprehensive coverage as the company grows. This approach is scalable and aligns with best practices for multi-account environments. Option 1 is incorrect because Security Hub aggregates findings but doesn't manage GuardDuty enablement or provide a centralized GuardDuty console for all accounts. Option 3 is incorrect as it suggests enabling Security Hub in each account, which doesn't centralize GuardDuty management or findings directly. Option 4 is incorrect because it focuses on Security Hub as the delegated administrator for Security Hub, not GuardDuty, and incorrectly suggests forwarding Security Hub findings to a GuardDuty account, which is not how the services integrate for centralized GuardDuty management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed