Auto-enable Security Hub for all accounts and aggregate findings across Regions

Answer Correct answer: A, C — turn on Security Hub auto-enable for all accounts and configure a finding aggregation Region to receive all-Region findings.

A company has AWS accounts that are in an organization in AWS Organizations. A security engineer needs to set up AWS Security Hub in a dedicated account for security monitoring. The security engineer must ensure that Security Hub automatically manages all existing accounts and all new accounts that are added to the organization. Security Hub also must receive findings from all AWS Regions. Which combination of actions will meet these requirements with the LEAST operational overhead? (Choose two.)

  1. Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region. Correct Answer
  2. Create an AWS Lambda function that routes events from other Regions to the dedicated Security Hub account. Create an Amazon EventBridge rule to invoke the Lambda function.
  3. Turn on the option to automatically enable accounts for Security Hub. Correct Answer
  4. Create an SCP that denies the securityhub:DisableSecurityHub permission. Attach the SCP to the organization’s root account.
  5. Configure services in other Regions to write events to an AWS CloudTrail organization trail. Configure Security Hub to read events from the trail.

Community Votes

AC
75%
CD
25%

75% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Security Hub's auto-enable membership (delegated admin) automatically enrolls all existing and newly created organization accounts, eliminating manual onboarding. Cross-Region finding aggregation links every Region's findings to one aggregation Region in the dedicated security account, providing organization- and Region-wide visibility with minimal operational effort.

Security Hub must centrally monitor a dedicated account, automatically cover existing and new organization accounts, and receive findings from all Regions with least overhead. Turning on Security Hub's auto-enable option makes every current and future account a member automatically. Configuring a finding aggregation Region and linking the other Regions funnels all Regions' findings into the dedicated account, satisfying both requirements without per-account SCP or Lambda work.

Adding an SCP that denies securityhub:DisableSecurityHub (option D). That is a preventative guardrail, not a mechanism to enable or aggregate accounts/Regions, and is unnecessary for the stated requirements. Or building Lambda/EventBridge routing (option B), which duplicates native auto-enable and aggregation.

Community Discussion (5 comments)

TareDHakim 👍 2 Selected: AC
D is a preventative method which isn't a requirement for this scenario.
IPLogic 👍 1 Selected: AC
To meet the requirements with the least operational overhead, the best combination of actions is: A. Configure a finding aggregation Region for Security Hub. Link the other Regions to the aggregation Region. C. Turn on the option to automatically enable accounts for Security Hub. These actions will ensure that Security Hub manages all existing and new accounts automatically and receives findings from all AWS Regions with minimal manual intervention.
jdx000 👍 1 Selected: CD
CD is the simplest way
Bad_Mat 👍 3
Roll back, AC
Bad_Mat 👍 1
I think CD

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C (auto-enable) ensures Security Hub is turned on for all existing and future organization accounts from the delegated admin account, meeting the automatic account-management requirement with no per-account action. A (finding aggregation Region) links all Regions so findings from every Region roll up into the dedicated security account, meeting the all-Regions requirement. Both are native, low-overhead settings.

Why the Other Options Are Wrong

B (Lambda + EventBridge routing) is unnecessary custom work that native aggregation already provides. D (SCP denying DisableSecurityHub) is a preventive guardrail, not an enablement or aggregation mechanism, and is not required by the scenario. E (organization trail) supports auditing but does not enable Security Hub or aggregate its findings.

Community Comment Notes

Community favored A,C (75 votes), noting D is preventative and not needed for the requirement. A minority argued C,D as "simplest," but D does not enable or aggregate accounts/Regions. AC is the least-overhead native pair.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide