AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A security engineer enables AWS Security Hub and wants it to automatically evaluate the account's configuration against a widely recognized set of security best practices, such as restricting root account usage and enforcing strong password policies. Which Security Hub feature should be enabled to achieve this?

  1. AA custom AWS Lambda function attached to CloudWatch Events
  2. BA security standard such as the CIS AWS Foundations Benchmark
  3. CAn AWS Config aggregator across multiple accounts
  4. DIAM Access Analyzer findings export
Show answer & explanation

Correct answer: B. A security standard such as the CIS AWS Foundations Benchmark

AWS Security Hub lets you enable industry-standard security standards, such as the CIS AWS Foundations Benchmark, which automatically run checks against best-practice controls (like root account restrictions and password policies) and report compliance status.

Why the other options are wrong

  • A. A custom Lambda function is not the built-in mechanism Security Hub uses for standards.
  • C. Config aggregators combine compliance data across accounts but aren't a Security Hub standard.
  • D. Access Analyzer findings relate to external resource sharing, not comprehensive best-practice benchmarks.

Security Hub Security Standards

AWS Security Hub can enable security standards such as the CIS AWS Foundations Benchmark, AWS Foundational Security Best Practices, and PCI DSS to automatically check account configuration against recognized frameworks.

  • Standards run automated checks and produce a compliance score
  • CIS AWS Foundations Benchmark is a widely recognized standard
  • Security Hub aggregates findings from GuardDuty, Inspector, Config, and more

Memory trick: Security Hub grades you against the industry rulebook

More Security and Compliance questions