Question 1 · choose 1
A company uses AWS Organizations with 140 member accounts and adds new accounts every month. The security team wants Amazon GuardDuty running in every existing and future account in the two Regions the company uses, with all findings visible from a security tooling account, and with as little ongoing work as possible. What should the team do?
- AMake the security tooling account the delegated GuardDuty administrator and set auto-enable to all accounts (ALL) in each Region
- BMake the security tooling account the delegated GuardDuty administrator and set auto-enable to new accounts only (NEW) in each Region
- CDeploy a CloudFormation StackSet that creates a GuardDuty detector in every account and in both Regions
- DEnable GuardDuty in the security tooling account in both Regions and invite every member account to join it
Show the answer and why
AMake the security tooling account the delegated GuardDuty administrator and set auto-enable to all accounts (ALL) in each Region
Correct
A delegated administrator sees the findings of its member accounts, and the ALL setting enables GuardDuty for existing accounts and for accounts that join later. Auto-enable preferences are set per Region.
BMake the security tooling account the delegated GuardDuty administrator and set auto-enable to new accounts only (NEW) in each Region
Incorrect
NEW enables GuardDuty only for accounts that join the organization after the setting is saved, so the 140 existing accounts stay uncovered.
CDeploy a CloudFormation StackSet that creates a GuardDuty detector in every account and in both Regions
Incorrect
Each account would run its own standalone detector. Findings are visible centrally only to an administrator account that has the other accounts as members, which a StackSet does not set up.
DEnable GuardDuty in the security tooling account in both Regions and invite every member account to join it
Incorrect
Invitations are the legacy method for accounts outside the organization. Each new account would need its own invitation, and GuardDuty recommends AWS Organizations instead.
Central management plus automatic coverage is the delegated administrator with auto-enable set to ALL. Choose NEW only when existing accounts are already handled some other way.
AWS documentation