Medium1 markMultiple Choice
Domain 1.2: Security ControlsGuardDutyOrganizationsSecurity

AWS SAP-C02 · Question 54 · Domain 1.2: Security Controls

An enterprise has 100 AWS accounts. They want to ensure that Amazon GuardDuty is enabled in every account and region, and that all findings are aggregated into a central 'Security Tooling' account. What is the MOST operationally efficient way to achieve this?

Answer options:

A.

Write a CloudFormation StackSet to deploy GuardDuty in all accounts.

B.

Designate the Security Tooling account as the GuardDuty delegated administrator in AWS Organizations, and enable GuardDuty for all accounts via the delegated admin.

C.

Use AWS Config rules to remediate accounts where GuardDuty is disabled.

D.

Manually invite each account from the Security Tooling account.

How to approach this question

Leverage AWS Organizations delegated administration.

Full Answer

B.Designate the Security Tooling account as the GuardDuty delegated administrator in AWS Organizations, and enable GuardDuty for all accounts via the delegated admin.✓ Correct
Many AWS security services (GuardDuty, Security Hub, Macie) support Delegated Administration via AWS Organizations. This allows a central security account to manage and aggregate findings for the entire organization automatically.

Common mistakes

Using manual invitations or custom scripts instead of native Org integration.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam