An organisation runs many AWS accounts under AWS Organizations and has already enabled GuardDuty, Inspector, and Macie. Security engineers are overwhelmed because findings are scattered across services and accounts, and leadership also wants a single view of how well each account conforms to a recognised security standard such as the AWS Foundational Security Best Practices. Which service should the team use to centralise and prioritise these findings and run automated standards checks?
- AAWS Security Hub, which aggregates findings from GuardDuty, Inspector, and Macie and runs automated checks against security standards Correct
- BAmazon GuardDuty, which collects findings from Inspector and Macie across all accounts and scores each account against a foundational security standard
- CAWS Config alone, which aggregates the GuardDuty, Inspector, and Macie findings into one view and scores each account against the security standard
- DAmazon Macie, which consolidates the GuardDuty and Inspector findings for every account and evaluates each one against the foundational security standard
Why A is correct: Security Hub ingests and normalises findings from GuardDuty, Inspector, Macie, and others across the organisation, deduplicates and prioritises them, and runs automated controls against standards such as the AWS Foundational Security Best Practices for a single posture view.
Why B is wrong: GuardDuty is a threat-detection source whose own findings feed elsewhere, so it seems central, but it does not aggregate other services' findings or run posture checks against a foundational security best practices standard.
Why C is wrong: Config records resource configuration and evaluates rules, and it underpins many checks, so it is tempting, but on its own it does not ingest and prioritise security findings from GuardDuty, Inspector, and Macie in a unified console.
Why D is wrong: Macie focuses on sensitive data discovery in S3 and contributes its own findings, so it is a finding producer rather than an aggregator, and it cannot centralise other services' results or run standards-based posture checks.