A new AWS Control Tower landing zone has been created inside an AWS Organization. The landing zone must demonstrate compliance with the CIS AWS Foundations benchmarks, and the security team should view aggregated Security Hub findings across all accounts (only the security team can view aggregated findings). Specific users must be able to view findings for their own accounts. All accounts must be automatically enrolled in Security Hub when created. Which set of steps, performed mostly automatically, will achieve this? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable trusted access for Security Hub from the organization’s management account. Create a new security account through AWS Control Tower, designate it as the delegated administrator for Security Hub, and configure Security Hub in that account with the CIS AWS Foundations standard., Create an AWS IAM Identity Center (AWS SSO) permission set that grants the required Security Hub permissions. Use the CreateAccountAssignment API to assign the security team users to that permission set and to the delegated security account., In Security Hub, enable automatic enablement so new accounts in the organization are enrolled automatically..
Why this is the answer
The correct options address the requirements for centralized security management, compliance, and user access. Enabling trusted access and designating a delegated administrator account for Security Hub allows for centralized aggregation of findings across the organization, which is necessary for the security team. Configuring the CIS AWS Foundations standard in this delegated account ensures compliance checks are performed. Creating an IAM Identity Center permission set and assigning it to the security team in the delegated account provides them with the necessary access to view aggregated findings. Enabling automatic enablement in Security Hub ensures that all new accounts are automatically enrolled, simplifying ongoing management. The incorrect options are less effective or incorrect. Enabling the CIS standard directly from the management account without a delegated administrator would not allow for centralized aggregation of findings for the security team. An SCP to deny access is overly restrictive and doesn't directly address the positive requirement of granting access to the security team. An EventBridge rule with a Lambda to call CreateMembers is a manual workaround for automatic enablement, which is a built-in Security Hub feature.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed