ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 303 - SCS-C02 discussion

Report
Export

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring.

The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions.

Which combination of actions will meet these requirements with the LEAST operational overhead? (Select TWO.)

A.
Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region.
Answers
A.
Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region.
B.
Create an AWS Lambda function that routes events from other Regions to the dedicated Security Hub account. Create an Amazon EventBridge rule to invoke the Lambda function.
Answers
B.
Create an AWS Lambda function that routes events from other Regions to the dedicated Security Hub account. Create an Amazon EventBridge rule to invoke the Lambda function.
C.
Turn on the option to automatically enable accounts for Security Hub.
Answers
C.
Turn on the option to automatically enable accounts for Security Hub.
D.
Create an SCP that denies the securityhub DisableSecurityHub permission. Attach the SCP to the organization's root account.
Answers
D.
Create an SCP that denies the securityhub DisableSecurityHub permission. Attach the SCP to the organization's root account.
E.
Configure services in other Regions to write events to an AWS CloudTrail organization trail. Configure Security Hub to read events from the trail.
Answers
E.
Configure services in other Regions to write events to an AWS CloudTrail organization trail. Configure Security Hub to read events from the trail.
Suggested answer: A, C

Explanation:

To set up AWS Security Hub for centralized security monitoring across all accounts in an AWS Organization with the least operational overhead, the best actions to take are:

Solution A: Configure a finding aggregation Region for Security Hub. This allows Security Hub to aggregate findings from multiple regions into a single designated region, simplifying monitoring and analysis. By centralizing findings, the security team can have a unified view of security alerts and compliance statuses across all accounts and regions, enhancing the efficiency of security operations.

Solution C: Turn on the option to automatically enable accounts for Security Hub within the AWS Organization. This ensures that as new accounts are created and added to the organization, they are automatically enrolled in Security Hub, and their findings are included in the centralized monitoring. This automation reduces the manual effort required to manage account enrollment and ensures comprehensive coverage of security monitoring across the organization.

These actions collectively ensure that Security Hub is effectively configured to manage security findings across all accounts and regions, providing a comprehensive and automated approach to security monitoring with minimal manual intervention.

asked 16/09/2024
Anu V
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first