AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A global enterprise uses multiple AWS accounts and regions for its operations. The security team needs to monitor security findings from various AWS services (e.g., GuardDuty, Inspector, Config, IAM Access Analyzer) from a single pane of glass. They also require automated remediation actions for certain high-severity findings. Which AWS service is best suited for aggregating these findings and orchestrating automated responses?
- AAmazon CloudWatch Dashboards
- BAWS Systems Manager OpsCenter
- CAWS Organizations
- DAWS Security Hub
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Security Hub
AWS Security Hub is designed to provide a comprehensive view of your security posture across your AWS accounts. It aggregates security findings from various AWS services, automates security checks, and integrates with other AWS services (like EventBridge and Lambda) to enable automated remediation.
Why the other options are wrong
- A. CloudWatch Dashboards can visualize metrics and logs, but they don't aggregate security *findings* from multiple security services or orchestrate automated remediation.
- B. AWS Systems Manager OpsCenter helps manage operational work items, but it's not the primary service for aggregating security findings from various AWS security services.
- C. AWS Organizations helps manage multiple AWS accounts but does not aggregate security findings or orchestrate automated responses.
AWS Security Hub
A cloud security posture management service that aggregates, organizes, and prioritizes security findings from multiple AWS services and partner solutions.
- Provides a single pane of glass for security posture.
- Automates security best practice checks.
- Integrates with Amazon EventBridge for automated remediation actions.
Memory trick: Security Hub gathers all risks in one place, then helps automate their chase.