Auto-enable Security Hub for all accounts and aggregate findings across Regions
A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring. The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions. Which combination of actions will meet these requirements with the LEAST operational overhead? (Choose two.)
Community Votes
75% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Security Hub's auto-enable membership (delegated admin) automatically enrolls all existing and newly created organization accounts, eliminating manual onboarding. Cross-Region finding aggregation links every Region's findings to one aggregation Region in the dedicated security account, providing organization- and Region-wide visibility with minimal operational effort.
Security Hub must centrally monitor a dedicated account, automatically cover existing and new organization accounts, and receive findings from all Regions with least overhead. Turning on Security Hub's auto-enable option makes every current and future account a member automatically. Configuring a finding aggregation Region and linking the other Regions funnels all Regions' findings into the dedicated account, satisfying both requirements without per-account SCP or Lambda work.
Adding an SCP that denies securityhub:DisableSecurityHub (option D). That is a preventative guardrail, not a mechanism to enable or aggregate accounts/Regions, and is unnecessary for the stated requirements. Or building Lambda/EventBridge routing (option B), which duplicates native auto-enable and aggregation.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.