For an AWS account already connected to Defender for Cloud, how should you enable AWS Foundational Security Best Practices while minimizing administrative effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign a built-in compliance standard..
Why this is the answer
Assigning a built-in compliance standard is the most efficient way to enable AWS Foundational Security Best Practices. Defender for Cloud includes pre-defined compliance standards that map to common security benchmarks, including AWS Foundational Security Best Practices. By assigning this standard, Defender for Cloud automatically monitors your AWS resources against these best practices, generating recommendations and alerts without requiring manual configuration. Creating a new custom standard or assessment would involve significant manual effort to define all the rules and checks, which is unnecessary when a built-in option exists. Assigning a built-in assessment is incorrect because assessments are components of standards; you assign the standard itself to enable the full set of best practices.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed