List of questions
Related questions
Question 303 - SCS-C02 discussion
A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring.
The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions.
Which combination of actions will meet these requirements with the LEAST operational overhead? (Select TWO.)
A.
Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region.
B.
Create an AWS Lambda function that routes events from other Regions to the dedicated Security Hub account. Create an Amazon EventBridge rule to invoke the Lambda function.
C.
Turn on the option to automatically enable accounts for Security Hub.
D.
Create an SCP that denies the securityhub DisableSecurityHub permission. Attach the SCP to the organization's root account.
E.
Configure services in other Regions to write events to an AWS CloudTrail organization trail. Configure Security Hub to read events from the trail.
Your answer:
0 comments
Sorted by
Leave a comment first