AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A company is standardizing its security posture across a multi-account AWS environment managed by AWS Organizations. A dedicated Security OU exists, which contains a Security Tooling account intended for centralized security operations. The company needs to implement a scalable solution to automatically detect software vulnerabilities and unintended network exposure for all EC2 instances and container images in ECR across all existing and future accounts within the organization. All security findings must be aggregated in a single place for streamlined analysis and reporting. Which approach is the most efficient and follows AWS best practices?

  • From the AWS Organizations management account, designate the Security Tooling account as the delegated administrator for Amazon Inspector. Then, from the Security Tooling account, enable Inspector and configure it to automatically manage all accounts in the organization. Integrate Amazon Inspector with AWS Security Hub in the Security Tooling account to centralize all findings.

  • In the AWS Organizations management account, enable Amazon Inspector and configure it to scan all member accounts. Configure AWS Security Hub in the management account and set it as the destination for all Inspector findings.

  • Deploy an AWS CloudFormation StackSet from the AWS Organizations management account to enable Amazon Inspector in every member account. Configure each Inspector instance to publish findings to a central Amazon S3 bucket via Amazon EventBridge. Use Amazon Athena in the Security Tooling account to query the findings.

  • Create an IAM role in each member account that grants the Security Tooling account permission to manage Amazon Inspector. Develop a custom script in the Security Tooling account that assumes this role in each member account to enable and configure Inspector.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot