A municipal Security Hub administrator account aggregates findings. Leadership requires that member accounts cannot silently mute critical GuardDuty findings from central view. What should the architect emphasize?
Select an answer to reveal the explanation.
Short Explanation
Central Security Hub is the city’s crime board—member desks should not quietly take critical pins off the map. Delegated admin plus org aggregation keeps GuardDuty severity visible upstairs. Isolated hubs, delayed GuardDuty enablement, or free-for-all suppressions undermine that visibility.
Full Explanation
AWS Security Hub supports a delegated administrator that aggregates findings across AWS Organizations accounts, pairing with organization-configured GuardDuty. That model preserves centralized visibility for critical findings so member accounts cannot quietly undermine org-wide risk posture through unchecked local suppression or by never enabling detectors. Isolated per-account hubs without aggregation, delaying GuardDuty auto-enable, or granting broad finding-update rights without governance conflict with the requirement that critical findings stay visible to the municipal security program.