Soru

Zorluk: ZorMulti-Account Governance and Organizational Structure

An enterprise is establishing centralized security monitoring across its multi-account environment using AWS Organizations. A solutions architect needs to configure Amazon GuardDuty so that all security alerts are consolidated into a dedicated Security Tooling member account. The solution must ensure that member accounts cannot disable GuardDuty or modify its configurations, while allowing the Security Tooling account to manage the service.

Arrange the following steps in the correct chronological sequence to implement this governance and security architecture.

  1. 1Enable trusted access for Amazon GuardDuty in AWS Organizations from the management account.
  2. 2Designate the dedicated Security Tooling account as the delegated administrator for Amazon GuardDuty from the management account.
  3. 3Attach a Service Control Policy (SCP) to the member Organizational Units (OUs) that denies GuardDuty disabling actions, exempting the delegated administrator role.
  4. 4Sign in to the Security Tooling account and enable GuardDuty, then configure it to automatically enable GuardDuty for all existing and new member accounts in the organization.

Cevap

The correct order of steps is to first enable trusted access for Amazon GuardDuty from the AWS Organizations management account, then designate the Security Tooling account as the delegated administrator from the management account. After delegation, attach a Service Control Policy (SCP) to the member OUs restricting GuardDuty modifications while exempting the delegated administrator. Finally, sign in to the Security Tooling account to enable GuardDuty and configure it to automatically enable the service for all current and future member accounts.
The correct sequence begins with the AWS Organizations management account enabling trusted access for GuardDuty, which is a prerequisite for delegation. The management account then registers the dedicated Security Tooling account as the delegated administrator. Next, the solutions architect secures the deployment by attaching an SCP to the member OUs to prevent local modification of GuardDuty settings, ensuring the delegated administrator role is exempted from this restriction. Finally, the solutions architect signs in to the Security Tooling account to enable the service and configure automatic onboarding for all current and future member accounts.

Adım Adım Çözüm

1
Enable trusted access for Amazon GuardDuty from the AWS Organizations management account.
Enables integration between AWS Organizations and Amazon GuardDuty.
Before a member account can be registered as a delegated administrator, the service principal must be granted trusted access to the Organization's structure.
2
Register the Security Tooling account as the delegated administrator for GuardDuty from the management account.
Grants the Security Tooling account permission to manage GuardDuty for the organization.
Delegated administration shifts operational control of the security service from the management account to the designated security account, adhering to the principle of least privilege.
3
Apply a Service Control Policy (SCP) to member OUs to prevent disabling GuardDuty.
Restricts member accounts from tampering with GuardDuty detector status, while allowing the delegated administrator role to perform its tasks.
SCPs establish organization-wide guardrails. To prevent member accounts from deleting or disabling the security monitoring, the policy must deny these APIs, while using a condition to exempt the admin role/account.
4
Enable and configure GuardDuty in the Security Tooling account to auto-enable for all member accounts.
Activates monitoring across all current and future member accounts.
With administrative authority delegated and governance guardrails active, the security tooling account can enable the service centrally and ensure immediate coverage for any new accounts joined to the organization.

Anahtar Kavram

Delegated administration and centralized security governance in AWS Organizations allow operational tasks to be securely managed from a dedicated security account, enforced by organization-wide SCP guardrails.
Tahmini Süre:3m 0s
Bu soruyu puanla