SCS-C02 exam dumps

SCS-C02 practice question 114 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 114

Select 3

Your organization uses AWS Security Hub to monitor and manage security across all AWS accounts in a multi-account setup. You are tasked with ensuring that Security Hub findings are automatically sent to a central S3 bucket across accounts for long-term archiving. Which of the following steps should you take to configure this setup correctly?

  1. A

    Enable Security Hub in the individual member accounts and link them to the administrator account.

  2. B

    Configure an S3 bucket policy in the central account to allow cross-account access for Security Hub findings.

  3. C

    Set up an EventBridge rule in the administrator account to capture Security Hub findings and route them to the central S3 bucket.

  4. D

    Enable AWS Config in all accounts to track compliance before setting up Security Hub.

  5. E

    Create an IAM role in the administrator account with permissions to write Security Hub findings to the S3 bucket.

Show answer and explanation

Correct answers: A, B, C

Explanation

To centralize and archive Security Hub findings from multiple AWS accounts, Security Hub must first be enabled in member accounts and linked to an administrator account. A central S3 bucket policy is required to allow cross-account access. Additionally, an EventBridge rule must be configured to capture and route Security Hub findings to the S3 bucket. AWS Config is unrelated to this specific task, and IAM roles are not needed for this purpose since the routing is managed by EventBridge.

  • A. Correct.

    Correct. Security Hub must be enabled in the member accounts and linked to the administrator account to centralize findings.

  • B. Correct.

    Correct. The S3 bucket policy needs to allow cross-account access to ensure findings from multiple accounts can be written to the central bucket.

  • C. Correct.

    Correct. An EventBridge rule is required to capture Security Hub findings and route them to a destination such as an S3 bucket.

  • D. Incorrect.

    Incorrect. While AWS Config is a useful service for compliance tracking, it is not a required step for setting up Security Hub or archiving findings.

  • E. Incorrect.

    Incorrect. An IAM role in this scenario is unnecessary because Security Hub findings are routed using EventBridge, not through direct IAM role actions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam