A municipality wants centralized detection of overly permissive IAM policies and unintended public resource exposure across all Organization accounts. Which security approach best provides these findings?
Select an answer to reveal the explanation.
Short Explanation
You cannot catch a door left open across fifty accounts with a yearly clipboard walk. Access Analyzer spots risky shares and wild policies; Security Hub rolls findings into one SOC view. Turning the detectors off just for peace and quiet is backwards.
Full Explanation
IAM Access Analyzer continuously evaluates resource and identity policies for external access and broad permissions, while AWS Security Hub centralizes security findings from Access Analyzer and other services across accounts. A delegated administrator security account is a common Organizations pattern for municipal SOCs. Periodic paper-only reviews and disabling analyzers leave continuous exposure undetected; broadening admin rights increases risk.