A security tooling account is the AWS Security Hub CSPM delegated administrator for 40 member accounts. Cross-Region aggregation is on, with us-east-1 as the home Region and eu-west-1 and ap-southeast-2 linked. The team needs EventBridge rules that page on-call for critical findings and ticket the rest, for findings raised in any account and any of the three Regions, with the fewest rule copies. Where should the rules be created?
Choose one.
Security Hub CSPM sends every new or updated finding to EventBridge as a "Security Hub Findings - Imported" event. An administrator account's event feed includes its member accounts' findings, and the home (aggregation) Region's feed includes findings from the linked Regions.
Two facts combine here. First, the administrator account sees finding events for all member accounts, so rules do not need to exist in each member. Second, with cross-Region aggregation the home Region's event feed carries findings from the linked Regions in near real time, so rules do not need to exist in each Region. One set of rules in the administrator account in us-east-1 therefore covers every account and Region. Creating rules in the other Regions too still works but duplicates coverage; rules in member accounts multiply the copies.
- Ask which account sees events for every member: the Security Hub CSPM administrator account.
- Ask which Region sees events for every Region: the home Region, once aggregation links the others.
- Combine the two: one rule set, administrator account, home Region.
- Reject the options that still work but multiply rule copies by Region or by account.
Exam tip: Security Hub CSPM alerting rules go in the administrator account in the home Region; aggregation already brings every account and linked Region there.
Designing Security Monitoring and Alerting Across an AWS Organization — the lesson that teaches this.