exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 419 discussion

A company creates an AWS Control Tower landing zone to manage and govern a multi-account AWS environment. The company's security team will deploy preventive controls and detective controls to monitor AWS services across all the accounts. The security team needs a centralized view of the security state of all the accounts.

Which solution will meet these requirements?

  • A. From the AWS Control Tower management account, use AWS CloudFormation StackSets to deploy an AWS Config conformance pack to all accounts in the organization.
  • B. Enable Amazon Detective for the organization in AWS Organizations. Designate one AWS account as the delegated administrator for Detective.
  • C. From the AWS Control Tower management account, deploy an AWS CloudFormation stack set that uses the automatic deployment option to enable Amazon Detective for the organization.
  • D. Enable AWS Security Hub for the organization in AWS Organizations. Designate one AWS account as the delegated administrator for Security Hub.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AzureDP900
5 months, 3 weeks ago
option D meets the requirements of providing a centralized view of the security state of all accounts: Centralized view: AWS Security Hub provides a unified view of security findings across multiple AWS services and accounts, making it easy to monitor the security posture of your organization. Delegated administration: By designating one account as the delegated administrator for Security Hub, you can centralize the management of Security Hub across all accounts in the organization. Integration with AWS Organizations: Enabling Security Hub at the organization level allows you to see the security findings from all member accounts in a single view.
upvoted 1 times
...
TonytheTiger
1 year, 1 month ago
Selected Answer: D
Option D: Enable AWS Security Hub and use Central Configuration for multiple AWS account and delegated Sec Hub Admin. "Central configuration is a Security Hub feature that helps you set up and manage Security Hub across multiple AWS accounts and AWS Regions & From the delegated Security Hub administrator account, you can specify how the Security Hub service, security standards, and security controls are configured in your organization accounts and organizational units (OUs) across Regions" (1) https://docs.aws.amazon.com/securityhub/latest/userguide/central-configuration-intro.html (2) https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-setup-prereqs.html
upvoted 2 times
...
career360guru
1 year, 1 month ago
Selected Answer: D
Option D
upvoted 1 times
...
a54b16f
1 year, 2 months ago
Selected Answer: D
centralized view == security hub
upvoted 3 times
...
adelynllllllllll
1 year, 2 months ago
D https://aws.amazon.com/blogs/mt/centralized-dashboard-for-aws-config-and-aws-security-hub/
upvoted 2 times
...
onlyvimal2103
1 year, 2 months ago
Correct Answer A https://aws.amazon.com/blogs/mt/extend-aws-control-tower-governance-using-aws-config-conformance-packs/
upvoted 1 times
...
kejam
1 year, 2 months ago
Selected Answer: D
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_integrate_delegated_admin.html
upvoted 3 times
...
alexis123456
1 year, 2 months ago
Correct Answer is D
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago