Enable AWS Security Hub across the organization with a delegated administrator

Answer Correct answer: D — Enable AWS Security Hub for the organization and designate a delegated administrator account for it.

A company creates an AWS Control Tower landing zone to manage and govern a multi-account AWS environment. The company's security team will deploy preventive controls and detective controls to monitor AWS services across all the accounts. The security team needs a centralized view of the security state of all the accounts. Which solution will meet these requirements?

  1. From the AWS Control Tower management account, use AWS CloudFormation StackSets to deploy an AWS Config conformance pack to all accounts in the organization.
  2. Enable Amazon Detective for the organization in AWS Organizations. Designate one AWS account as the delegated administrator for Detective.
  3. From the AWS Control Tower management account, deploy an AWS CloudFormation stack set that uses the automatic deployment option to enable Amazon Detective for the organization.
  4. Enable AWS Security Hub for the organization in AWS Organizations. Designate one AWS account as the delegated administrator for Security Hub. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Security Hub is the service built to aggregate security findings into one dashboard across accounts, and enabling it at the organization level with a delegated administrator is what makes the aggregated view populate with findings from every member account.

A company has created an AWS Control Tower landing zone and its security team will deploy preventive and detective controls across all accounts in the organization. The team needs a single centralized view of the security posture of every account.

Using CloudFormation StackSets to deploy a Config conformance pack. A conformance pack evaluates resource configuration compliance and reports results, but it is not a security findings aggregation service, so it does not produce the cross-account security state view that the requirement asks for.

Community Discussion (8 comments)

AzureDP900 👍 1
option D meets the requirements of providing a centralized view of the security state of all accounts: Centralized view: AWS Security Hub provides a unified view of security findings across multiple AWS services and accounts, making it easy to monitor the security posture of your organization. Delegated administration: By designating one account as the delegated administrator for Security Hub, you can centralize the management of Security Hub across all accounts in the organization. Integration with AWS Organizations: Enabling Security Hub at the organization level allows you to see the security findings from all member accounts in a single view.
TonytheTiger 👍 2 Selected: D
Option D: Enable AWS Security Hub and use Central Configuration for multiple AWS account and delegated Sec Hub Admin. "Central configuration is a Security Hub feature that helps you set up and manage Security Hub across multiple AWS accounts and AWS Regions & From the delegated Security Hub administrator account, you can specify how the Security Hub service, security standards, and security controls are configured in your organization accounts and organizational units (OUs) across Regions" (1) https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html (2) https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-setup-prereqs.html
career360guru 👍 1 Selected: D
Option D
a54b16f 👍 3 Selected: D
centralized view == security hub
adelynllllllllll 👍 2
D https://aws.amazon.com/blogs/mt/centralized-dashboard-for-aws-config-and-aws-security-hub/
onlyvimal2103 👍 1
Correct Answer A https://aws.amazon.com/blogs/mt/extend-aws-control-tower-governance-using-aws-config-conformance-packs/
kejam 👍 3 Selected: D
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_integrate_delegated_admin.html
alexis123456 👍 3
Correct Answer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Security Hub aggregates security findings from AWS services and partner products into a single dashboard, and enabling it in AWS Organizations with a designated delegated administrator automatically enrolls and configures every account in the organization. The security team then has one place to see findings and the security state across all accounts, which is exactly the centralized view required, and the delegated administrator account is where the configuration and membership are managed.

Why the Other Options Are Wrong

A: A Config conformance pack deployed through CloudFormation StackSets does evaluate and report configuration compliance across accounts, but Config is a configuration service rather than a security findings aggregation service, so it does not provide the consolidated security state view the requirement describes. B: Amazon Detective is for investigating and analyzing security findings to determine root causes, and by itself it is not the cross-account security posture dashboard the team needs for monitoring all accounts. C: Deploying a stack set to enable Detective would turn the service on but still would not deliver the aggregated security state view, and Detective's value is investigation rather than posture monitoring.

Community Comment Notes

The community voted 100 to 0 for D, and commenters noted that a centralized view is the signature use case for Security Hub, with one linking an AWS blog on a centralized dashboard combining AWS Config and AWS Security Hub and another pointing out that Central Configuration with a delegated Security Hub administrator is the multi-account setup feature.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide