SCS-C02 Question 430
Single answerYour organization uses AWS Organizations to manage multiple accounts. The security team wants to delegate specific security-related tasks, such as managing AWS Config rules and Amazon GuardDuty findings, to a dedicated account. Which managed AWS service allows for this kind of delegated administration?
- A
AWS IAM
- B
AWS Security Hub
- C
AWS Organizations
- D
AWS Config
Show answer and explanation
Correct answer: B
Explanation
AWS Security Hub supports delegated administration within AWS Organizations. This allows an organization's management account to assign certain security-related tasks to a designated member account, which can then manage security findings and insights across the organization. This feature facilitates centralized security management while allowing specific tasks to be distributed to specialized accounts.
- A. Incorrect.
AWS IAM is used for identity and access management, not for delegating administration across accounts in AWS Organizations.
- B. Correct.
AWS Security Hub supports delegated administration, allowing specific security tasks like managing findings to be handled by a delegated account.
- C. Incorrect.
AWS Organizations is a service for managing multiple accounts but does not directly provide functionality for delegated administration of security tasks.
- D. Incorrect.
AWS Config provides configuration tracking and compliance evaluation but does not enable delegated administration across accounts.