BlueFerry Insurance uses AWS Organizations with 40 accounts across multiple Regions. Compliance requires a single Security Hub view in account SecAdmin (us-east-1) that aggregates findings from all member accounts and Regions with minimal operational overhead and no custom cross-account forwarding. What should the security architect do?
Choose an answer
Tap an option to check your answer.
Correct answer: Designate SecAdmin as the Security Hub delegated administrator in Organizations, enable (and auto-enable) Security Hub in all member accounts and Regions, then in SecAdmin us-east-1 create a cross-Region finding aggregator resource that aggregates findings from all enabled Regions..
Why this is the answer
The correct answer leverages Security Hub's native multi-account and multi-Region aggregation capabilities. Designating SecAdmin as the delegated administrator allows centralized management and viewing of findings from all member accounts. Enabling Security Hub in all accounts and Regions ensures comprehensive coverage. The cross-Region finding aggregator resource in SecAdmin (us-east-1) then consolidates all these findings into a single, unified view without requiring custom forwarding or additional services, meeting the requirement for minimal operational overhead. Incorrect options: EventBridge rules for forwarding findings would introduce significant operational overhead due to the need to configure and manage rules in every account and Region. AWS Config aggregators are for AWS Config rules and compliance data, not for Security Hub findings. Security Hub does not automatically pull findings from other Regions into a home Region; explicit cross-Region aggregation is required.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed