A company has an AWS Organizations structure with a management account and 40 member accounts grouped into four OUs. The security team wants a single AWS account to receive all Amazon GuardDuty findings from every account and to view them in one place. They also need new accounts created under any OU to be automatically enrolled. Which solution meets these requirements with the LEAST operational overhead?
GuardDuty integrates natively with AWS Organizations. Designating a delegated administrator lets that account manage GuardDuty across the organization, and auto-enable ensures every current and future member account is protected and its findings are aggregated in the delegated administrator account with no per-account scripting.
Why this answer
GuardDuty's native AWS Organizations integration is the intended mechanism for multi-account security monitoring. A delegated administrator account manages the service centrally, and auto-enable covers both existing accounts and accounts created later under any OU. This avoids building and maintaining per-account EventBridge and SNS forwarding pipelines while still delivering a consolidated findings view.
Exam trap
The trap here is assuming GuardDuty detectors can be shared across accounts with AWS Resource Access Manager instead of using the built-in Organizations delegated administrator and auto-enable features.