AnswerCorrect answer: B, D, E — delegated admin + EventBridge, Firehose to a single S3 bucket, and Athena/QuickSight for the correlated dashboard.
An international company wants to combine AWS Security Hub findings across all the company's AWS Regions and from multiple accounts. In addition, the company wants to create a centralized custom dashboard to correlate these findings with operational data for deeper analysis and insights. The company needs an analytics tool to search and visualize Security Hub findings. Which combination of steps will meet these requirements? (Chose three.)
Designate an AWS account as a delegated administrator for Security Hub. Publish events to Amazon CloudWatch from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings.
Designate an AWS account in an organization in AWS Organizations as a delegated administrator for Security Hub. Publish events to Amazon EventBridge from the delegated administrator account, all member accounts, and required Regions that are enabled for Security Hub findings. Correct Answer
In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis data stream. Configure the Kinesis data streams to output the logs to a single Amazon S3 bucket.
In each Region, create an Amazon EventBridge rule to deliver findings to an Amazon Kinesis Data Firehose delivery stream. Configure the Kinesis Data Firehose delivery streams to deliver the logs to a single Amazon S3 bucket. Correct Answer
Use AWS Glue DataBrew to crawl the Amazon S3 bucket and build the schema. Use AWS Glue Data Catalog to query the data and create views to flatten nested attributes. Build Amazon QuickSight dashboards by using Amazon Athena. Correct Answer
Community Insight
Security Hub delegated administration aggregates findings org-wide; EventBridge is the correct event bus (not CloudWatch). Firehose (not Data Streams) is the managed delivery stream that persists findings to S3 without building consumer apps. Athena over the S3 data lake plus QuickSight provides the search/visualization layer the analytics requirement needs.
The company needs Security Hub findings combined across all accounts and Regions and visualized on a custom dashboard with operational data. The solution: designate a Security Hub delegated administrator in the organization and publish findings to EventBridge; in each Region, an EventBridge rule sends findings to a Kinesis Data Firehose delivery stream that lands them in a single S3 bucket; Athena queries that bucket and QuickSight builds the correlated dashboard. CloudWatch (A) and Kinesis Data Streams (C) are the wrong delivery primitives.
Choosing CloudWatch publishing (A) instead of EventBridge, or Kinesis Data Streams (C) instead of Firehose—Data Streams needs a custom consumer to land data in S3, while Firehose delivers to S3 natively. Both A and C use the wrong transport for a managed S3 lake.
Community Discussion (6 comments)
ion_gee👍 2Selected: BD
Not A, do not need cloud watch. Not C, Kinesis Data firehose(Now Amazon Data Firehose) is what we need here, not Kinesis Data Streams. Not E . Rather use Athena to query S3 See Ref https://aws.amazon.com/blogs/architecture/visualize-aws-security-hub-findings-using-analytics-and-business-intelligence-tools/
ale_brd_111👍 1Selected: BD
BDF probably
nublit👍 1Selected: BD
BDF are the best options
awssecuritynewbie👍 1Selected: BD
BDF for sure,
sarcactus👍 1Selected: BD
BDF Also agree with previous comment.
MikeRach👍 1
BDF The steps are literally provided in this Doc https://aws.amazon.com/blogs/architecture/visualize-aws-security-hub-findings-using-analytics-and-business-intelligence-tools/
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
B establishes the delegated administrator and EventBridge publishing so findings from all accounts/Regions flow through one bus. D uses per-Region EventBridge rules to Firehose delivery streams that consolidate findings into a single S3 bucket—the managed path to a data lake. E uses Glue/Athena to query the S3 data and QuickSight to build the correlated dashboard, meeting the analytics and visualization requirement. Together they cover aggregation, storage, and insight.
Why the Other Options Are Wrong
A publishes to CloudWatch, which is not the finding-distribution mechanism Security Hub uses for cross-account analytics. C uses Kinesis Data Streams, which would require a custom consumer to write to S3; Firehose (D) does this natively. The B/D/E combination is the documented, lowest-effort pipeline.
Community Comment Notes
Commenters concluded B/D/(F) referencing the AWS architecture blog for visualizing Security Hub findings with analytics/BI tools; in this five-option set the analytics step is E (Glue/Athena/QuickSight). A and C are explicitly rejected for using CloudWatch and Data Streams instead of EventBridge and Firehose. The correct trio is B, D, E.