SAP-C02 Question 66
Single answerYour company operates a multi-account AWS environment using AWS Organizations. Recently, a third-party security auditor recommended improving threat detection and compliance monitoring across all accounts. The company wants a centralized, managed solution to aggregate findings from multiple AWS services like Amazon Inspector, AWS Config, and AWS CloudTrail. Additionally, the solution should provide insights and remediation recommendations for detected security issues. Which AWS service should you use to meet these requirements?
- A
AWS Security Hub
- B
AWS CloudTrail
- C
AWS Identity and Access Management (IAM) Access Analyzer
- D
Amazon Macie
Show answer and explanation
Correct answer: A
Explanation
AWS Security Hub is a managed service that provides a comprehensive view of security and compliance across AWS accounts. It integrates with other AWS services like Amazon Inspector, AWS Config, and AWS CloudTrail to aggregate findings, provide security insights, and recommend remediations. This makes it the best solution for centralized security and compliance monitoring in a multi-account AWS environment.
- A. Correct.
AWS Security Hub is designed for centralized threat detection, compliance monitoring, and aggregation of findings from multiple AWS services, making it the optimal choice for this scenario.
- B. Incorrect.
AWS CloudTrail provides logging and monitoring of API activity but does not offer centralized aggregation of findings or remediation recommendations.
- C. Incorrect.
AWS Identity and Access Management (IAM) Access Analyzer helps identify overly permissive IAM policies but does not provide a centralized security and compliance view.
- D. Incorrect.
Amazon Macie is focused on discovering and protecting sensitive data, such as personally identifiable information (PII), but does not serve as a centralized security and compliance monitoring solution.