Auto-enroll all org accounts in Security Hub via a delegated admin and a configuration policy on the org root

Answer Correct answer: D — a Security Hub delegated admin plus a configuration policy on the org root auto-enrolls all current and new accounts.

A company has a multi-account strategy that uses an organization in AWS Organizations with all features enabled. The company has enabled trusted access for AWS Account Management. New accounts are provisioned through AWS Control Tower Account Factory. The company must ensure that all new accounts in the organization become AWS Security Hub member accounts. Which solution will meet these requirements with the LEAST development effort?

  1. Enable Security Hub in the organization’s management account. Create an AWS Step Functions workflow. Create an Amazon EventBridge rule to invoke the workflow when a CreateAccount event occurs.
  2. Enable Security Hub in the organization’s management account. Wait for all new accounts to complete automatic onboarding.
  3. Enable Security Hub in the organization’s management account. Create an AWS Lambda function to enable Security Hub for new accounts. Invoke the Lambda function by using an AWS Control Tower lifecycle event that occurs when a new account is provisioned.
  4. Use the organization’s management account to designate a Security Hub delegated administrator account. In the delegated administrator account, create a configuration policy to enable Security Hub. Associate the configuration policy with the organization root. Correct Answer

Community Votes

D
67%
B
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Security Hub configuration policies are the native, code-free way to enable and standardize Security Hub across an organization; associating a policy with the root covers all current and newly created accounts automatically. This avoids the custom automation (Step Functions/EventBridge or Lambda/Control Tower lifecycle) that options A and C require.

All new Control Tower-provisioned accounts must become Security Hub members with the least development effort. Designating a Security Hub delegated administrator account and creating a Security Hub configuration policy that enables Security Hub, then associating that policy with the organization root, automatically applies and enforces Security Hub membership for every existing and future account—no custom Lambda, Step Functions, or per-account onboarding needed.

Assuming that merely enabling Security Hub in the management account auto-onboards new accounts (option B)—without a delegated admin and configuration policy (or auto-enable), new accounts are not automatically enrolled. Building Step Functions/Lambda workflows (A/C) adds development effort the scenario wants to avoid.

Community Discussion (7 comments)

woonsi 👍 1 Selected: D
How Option D Works: 1. Designate a Delegated Administrator Account • In the AWS Organizations management account, set a Security Hub delegated administrator account (e.g., a security account). • This centralizes management of Security Hub across all accounts. 2. Create a Security Hub Configuration Policy in the Delegated Administrator Account • Security Hub provides configuration policies that automatically enable Security Hub for all existing and future accounts in the organization. 3. Associate the Policy with the Organization Root • This ensures that every new AWS account automatically joins Security Hub without requiring any manual intervention or custom automation.
youonebe 👍 1 Selected: B
Answer B AWS Security Hub offers an automatic onboarding feature when it is enabled in the organization’s management account. New accounts created under AWS Organizations can automatically be onboarded into Security Hub, so they become member accounts as long as the management account has Security Hub enabled and the accounts are part of the same organization. No extra configuration or development is needed.
TareDHakim 👍 2 Selected: D
it not B. because new accounts need to be configured the appropriate settings with a delegated administrator or create automation to enable Security Hub. This answer is incomplete.
Asma2023 👍 1 Selected: B
New accounts are automatically enrolled as member accounts
Pmktechno 👍 1 Selected: B
When Security Hub is enabled in the organization's management account, new accounts are automatically enrolled as member accounts. This approach minimizes the need for additional configuration or custom development, ensuring that all new accounts are seamlessly integrated into Security Hub.
0adbfdf 👍 1 Selected: D
D makes the most sense
k23319 👍 2 Selected: D
It's best practice to designate a delegated security administrator account. https://docs.aws.amazon.com/securityhub/latest/userguide/designate-orgs-admin-account.html https://docs.aws.amazon.com/securityhub/latest/userguide/create-associate-policy.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Designating a delegated administrator account and attaching a Security Hub configuration policy to the organization root enables Security Hub for all accounts in the org and automatically enforces it on every new account added later. This is the least-development-effort, managed mechanism and directly satisfies the requirement.

Why the Other Options Are Wrong

B is wrong because enabling Security Hub in the management account alone does not auto-enroll new accounts; a configuration policy or auto-enable setting is required. A and C build custom orchestration (Step Functions/EventBridge or Lambda on Control Tower lifecycle events), which works but adds development and maintenance effort contrary to the 'least development effort' requirement.

Community Comment Notes

Community favored D (67 votes). Commenters noted B is incomplete (new accounts need configuration via delegated admin or automation) and that a configuration policy on the org root is best practice for automatic, code-free enrollment. A minority picked B believing in auto-onboarding, but D is the complete native solution.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide