exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 183 discussion

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring.

The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions.

Which combination of actions will meet these requirements with the LEAST operational overhead? (Choose two.)

  • A. Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region.
  • B. Create an AWS Lambda function that routes events from other Regions to the dedicated Security Hub account. Create an Amazon EventBridge rule to invoke the Lambda function.
  • C. Turn on the option to automatically enable accounts for Security Hub.
  • D. Create an SCP that denies the securityhub:DisableSecurityHub permission. Attach the SCP to the organization’s root account.
  • E. Configure services in other Regions to write events to an AWS CloudTrail organization trail. Configure Security Hub to read events from the trail.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TareDHakim
3 months, 3 weeks ago
Selected Answer: AC
D is a preventative method which isn't a requirement for this scenario.
upvoted 2 times
...
IPLogic
4 months, 3 weeks ago
Selected Answer: AC
To meet the requirements with the least operational overhead, the best combination of actions is: A. Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region. C. Turn on the option to automatically enable accounts for Security Hub. These actions will ensure that Security Hub manages all existing and new accounts automatically and receives findings from all AWS Regions with minimal manual intervention.
upvoted 1 times
...
jdx000
4 months, 4 weeks ago
Selected Answer: CD
CD is the simplest way
upvoted 1 times
...
Bad_Mat
6 months ago
Roll back, AC
upvoted 3 times
...
Bad_Mat
6 months ago
I think CD
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago