Enable AWS Security Hub across the organization with a delegated administrator
A company creates an AWS Control Tower landing zone to manage and govern a multi-account AWS environment. The company's security team will deploy preventive controls and detective controls to monitor AWS services across all the accounts. The security team needs a centralized view of the security state of all the accounts. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Security Hub is the service built to aggregate security findings into one dashboard across accounts, and enabling it at the organization level with a delegated administrator is what makes the aggregated view populate with findings from every member account.
A company has created an AWS Control Tower landing zone and its security team will deploy preventive and detective controls across all accounts in the organization. The team needs a single centralized view of the security posture of every account.
Using CloudFormation StackSets to deploy a Config conformance pack. A conformance pack evaluates resource configuration compliance and reports results, but it is not a security findings aggregation service, so it does not produce the cross-account security state view that the requirement asks for.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Security Hub aggregates security findings from AWS services and partner products into a single dashboard, and enabling it in AWS Organizations with a designated delegated administrator automatically enrolls and configures every account in the organization. The security team then has one place to see findings and the security state across all accounts, which is exactly the centralized view required, and the delegated administrator account is where the configuration and membership are managed.Why the Other Options Are Wrong
A: A Config conformance pack deployed through CloudFormation StackSets does evaluate and report configuration compliance across accounts, but Config is a configuration service rather than a security findings aggregation service, so it does not provide the consolidated security state view the requirement describes. B: Amazon Detective is for investigating and analyzing security findings to determine root causes, and by itself it is not the cross-account security posture dashboard the team needs for monitoring all accounts. C: Deploying a stack set to enable Detective would turn the service on but still would not deliver the aggregated security state view, and Detective's value is investigation rather than posture monitoring.Community Comment Notes
The community voted 100 to 0 for D, and commenters noted that a centralized view is the signature use case for Security Hub, with one linking an AWS blog on a centralized dashboard combining AWS Config and AWS Security Hub and another pointing out that Central Configuration with a delegated Security Hub administrator is the multi-account setup feature.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →