AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A company operates 15 AWS accounts in a single AWS organization. The security team maintains a dedicated Security account and wants a near-real-time notification whenever a high-severity security event (such as an IAM policy change, an AWS Config compliance failure, or a critical Amazon GuardDuty finding) occurs in any account. The notifications must be delivered to the Security account, analysts must be able to review historical findings for at least 90 days, and ongoing maintenance in member accounts must be minimized. Which solution should a solutions architect implement to meet these requirements?

  • Create an individual CloudTrail trail in every account that writes logs to a centralized Amazon S3 bucket in the Security account; configure Amazon S3 event notifications to invoke a Lambda function that scans new log files for high-severity events and sends notifications through Amazon SNS.

  • Designate the Security account as the delegated administrator for AWS Security Hub, enable Security Hub (and its GuardDuty integration) across the organization, and create an Amazon EventBridge rule in the Security account that filters for HIGH and CRITICAL findings and publishes them to an Amazon SNS topic subscribed by the security team.

  • Enable an AWS Config organization aggregator in the Security account, enable all AWS Config rules and Amazon GuardDuty in every account, and configure AWS Config to stream compliance change notifications to an Amazon SNS topic in the Security account.

  • Configure an AWS Organizations CloudTrail organization trail that delivers management events to Amazon CloudWatch Logs in every account; in each account create a subscription filter that streams the log data to a Kinesis Data Firehose delivery stream in the Security account, where an AWS Lambda function parses the stream and publishes high-severity events to Amazon SNS.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot