The security team wants a native AWS service to continuously assess all member accounts in an AWS Organization against the CIS AWS Foundations Benchmark. Which approach is the most operationally efficient?
Choose an answer
Tap an option to check your answer.
Correct answer: Designate an AWS Security Hub administrator account, enable automatic enrollment of new accounts as member accounts, and enable the CIS AWS Foundations Benchmark checks..
Why this is the answer
The most operationally efficient approach is to designate an AWS Security Hub administrator account, enable automatic enrollment of new accounts as member accounts, and enable the CIS AWS Foundations Benchmark checks. Security Hub is designed for continuous security posture management across multiple accounts and natively supports the CIS AWS Foundations Benchmark. Automatic enrollment simplifies management by ensuring new accounts are automatically included. Incorrect options: Scripting invitations and acceptances for each account is less efficient than automatic enrollment, especially in a dynamic environment. Amazon Inspector focuses on vulnerability management for EC2 instances and container images, not continuous compliance against benchmarks for the entire AWS environment. GuardDuty is a threat detection service, not a compliance assessment tool for benchmarks like CIS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed