AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company utilizes a multi-account AWS environment managed through AWS Organizations. The Chief Information Security Officer (CISO) has mandated a new initiative to enhance the security posture across all accounts. The primary goals are to establish a centralized dashboard for all security and compliance findings from services like Amazon GuardDuty and AWS Config, and to address two critical requirements:

  1. Continuously and automatically scan all Amazon EC2 instances and container images in Amazon ECR for software vulnerabilities and unintended network exposure.
  2. Proactively identify any resource-based policies (e.g., on S3 buckets or IAM roles) that grant access to external entities outside of their AWS Organization.

Which combination of AWS services should a solutions architect propose to meet all these requirements in the most integrated and efficient manner?

  • Deploy an AWS CloudTrail organization trail, and configure Amazon Detective and Amazon Inspector in all accounts.

  • Enable AWS Security Hub as a delegated administrator, and configure Amazon Inspector and AWS IAM Access Analyzer in all accounts.

  • Enable AWS Security Hub as a delegated administrator, and configure AWS Systems Manager Patch Manager and AWS IAM Access Analyzer in all accounts.

  • Enable AWS Security Hub as a delegated administrator, and configure Amazon Inspector and AWS Trusted Advisor in all accounts.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot