SCS-C02 exam dumps

SCS-C02 practice question 52 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 52

Select 3

An organization uses multiple AWS accounts for different business units and has enabled AWS Security Hub in each account. They want to centralize all security findings from these accounts into a single account for easier monitoring and incident response. Which of the following strategies can help achieve this goal?

  1. A

    Enable Security Hub cross-account aggregation by designating an administrator account.

  2. B

    Use Amazon CloudWatch Events to forward findings from all accounts to a central S3 bucket.

  3. C

    Configure AWS Organizations and enable Security Hub integration across all member accounts.

  4. D

    Set up an AWS Lambda function in each account to push Security Hub findings to a central DynamoDB table.

  5. E

    Use EventBridge to route Security Hub findings from member accounts to the central account.

Show answer and explanation

Correct answers: A, C, E

Explanation

To centralize security findings in AWS, you can use Security Hub's cross-account aggregation feature by designating an administrator account. Additionally, integrating Security Hub with AWS Organizations simplifies setup and management across multiple accounts. EventBridge can also be used to route findings to the central account for additional processing or visualization. These methods are scalable and align with AWS best practices for security findings centralization.

  • A. Correct.

    Correct: Security Hub cross-account aggregation allows you to designate an administrator account, which can automatically aggregate findings from member accounts into a single view.

  • B. Incorrect.

    Incorrect: CloudWatch Events is not the recommended approach for forwarding Security Hub findings. Security Hub provides native mechanisms for cross-account aggregation.

  • C. Correct.

    Correct: Integrating Security Hub with AWS Organizations allows you to centrally manage member accounts and enables findings aggregation in the designated administrator account.

  • D. Incorrect.

    Incorrect: Using an AWS Lambda function to push findings to a central DynamoDB table is not an efficient or scalable strategy, as Security Hub already provides native cross-account aggregation features.

  • E. Correct.

    Correct: EventBridge can be used to route Security Hub findings to a central account, as it allows event-based routing across accounts and regions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam