AWS Certified Solutions Architect Professional SAP-C02 Practice Question

An enterprise uses AWS Organizations to manage more than 500 AWS accounts. The security team has created a dedicated security-tooling account in the us-east-1 Region and must meet the following requirements:

  1. AWS Security Hub must be enabled in every current and future account in all Regions.
  2. All findings must be visible only in the security-tooling account.
  3. No other account may designate itself as the Security Hub delegated administrator. The solution must follow the principle of least privilege and require minimal ongoing maintenance. Which approach BEST meets these requirements?
  • From the organization management account, run securityhub enable-organization-admin-account in each enabled Region to set the security-tooling account as delegated administrator. In the delegated administrator account, run securityhub update-organization-configuration with AutoEnable=true and enable the default standards for all Regions. Attach an SCP at the organization root that denies securityhub:EnableOrganizationAdminAccount to every account except the management account.

  • Use a CloudFormation StackSet to deploy a template that enables Security Hub and its default standards in every current account and Region; configure the StackSet for automatic deployment to new accounts.

  • Enable Security Hub through AWS Control Tower guardrails when the landing zone is set up. Rely on the guardrails to enable Security Hub in new accounts and prevent changes to the delegated administrator.

  • Enable Security Hub only in the security-tooling account and create a cross-Region finding aggregator. In each member account, add an EventBridge rule that forwards Security Hub findings to the aggregator.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot