AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A company is standardizing its security posture across a multi-account AWS environment managed by AWS Organizations. A dedicated Security OU exists, which contains a Security Tooling account intended for centralized security operations. The company needs to implement a scalable solution to automatically detect software vulnerabilities and unintended network exposure for all EC2 instances and container images in ECR across all existing and future accounts within the organization. All security findings must be aggregated in a single place for streamlined analysis and reporting. Which approach is the most efficient and follows AWS best practices?
From the AWS Organizations management account, designate the Security Tooling account as the delegated administrator for Amazon Inspector. Then, from the Security Tooling account, enable Inspector and configure it to automatically manage all accounts in the organization. Integrate Amazon Inspector with AWS Security Hub in the Security Tooling account to centralize all findings.
In the AWS Organizations management account, enable Amazon Inspector and configure it to scan all member accounts. Configure AWS Security Hub in the management account and set it as the destination for all Inspector findings.
Deploy an AWS CloudFormation StackSet from the AWS Organizations management account to enable Amazon Inspector in every member account. Configure each Inspector instance to publish findings to a central Amazon S3 bucket via Amazon EventBridge. Use Amazon Athena in the Security Tooling account to query the findings.
Create an IAM role in each member account that grants the Security Tooling account permission to manage Amazon Inspector. Develop a custom script in the Security Tooling account that assumes this role in each member account to enable and configure Inspector.
The correct approach involves leveraging the native integration between AWS Organizations, Amazon Inspector, and AWS Security Hub for a centralized and scalable security model. The first step is to designate a specific account for security operations, in this case, the Security Tooling account, as the delegated administrator for Amazon Inspector. This action must be performed from the AWS Organizations management account. Once delegated, the Security Tooling account can manage Inspector for all member accounts, including enabling scans and configuring settings. To centralize findings, Amazon Inspector should be integrated with AWS Security Hub. When both are enabled, Inspector automatically sends all findings to Security Hub, which aggregates them from across the organization. This provides a single pane of glass for security analysis, which fulfills the company's requirement for streamlined reporting.
Using the management account for operational security tasks like managing Inspector and Security Hub is against AWS best practices, which recommend that the management account be used for billing and account management only. While a CloudFormation StackSet or custom scripts could be used to enable Inspector, these methods are less efficient and scalable than using the built-in AWS Organizations integration, which automatically handles new accounts. The native integration with Security Hub is also more efficient for aggregating findings than building a custom solution with S3 and Athena.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What role does the Security Tooling account play in this solution?
Open an interactive chat with Bash
What is Amazon Inspector, and how does it detect vulnerabilities?
Open an interactive chat with Bash
Why is AWS Security Hub important in this architecture?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access