AWS SAP-C02 · Question 54 · Domain 1.2: Security Controls
An enterprise has 100 AWS accounts. They want to ensure that Amazon GuardDuty is enabled in every account and region, and that all findings are aggregated into a central 'Security Tooling' account. What is the MOST operationally efficient way to achieve this?
Answer options:
Write a CloudFormation StackSet to deploy GuardDuty in all accounts.
Designate the Security Tooling account as the GuardDuty delegated administrator in AWS Organizations, and enable GuardDuty for all accounts via the delegated admin.
Use AWS Config rules to remediate accounts where GuardDuty is disabled.
Manually invite each account from the Security Tooling account.
75 questions · hints · full answers · grading