Courseiva

Why GuardDuty Findings Are Not Displaying in Security Hub from Member Accounts and How to Fix It

A company has a multi-account AWS environment using AWS Organizations. The security team uses AWS Security Hub to consolidate findings. They notice that a critical finding in the production account is not being aggregated in Security Hub. The finding is generated by Amazon GuardDuty. What is the MOST likely cause?

⚠ Common exam trap

Many exam-takers assume Security Hub automatically enables or integrates with all security services across accounts, but in reality, each service (like GuardDuty) must be individually enabled in each account for its findings to be aggregated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty is not enabled in the production account.

Amazon Security Hub aggregates findings from enabled security services across accounts. For GuardDuty findings to appear in Security Hub, GuardDuty must be enabled in the account where the finding is generated. If GuardDuty is not enabled in the production account, it cannot produce findings for Security Hub to consume, which is the most likely cause of the missing critical finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon GuardDuty is not enabled in the production account.

    Why this is correct

    GuardDuty is the source service that produces the security findings in question. Security Hub is purely an aggregator: it ingests findings from GuardDuty only when GuardDuty is actually enabled and actively detecting threats in the account. If GuardDuty is not enabled in the production account, it generates no findings, so Security Hub has nothing to aggregate, regardless of how correctly Security Hub and cross-account roles are configured. Enabling Security Hub does not automatically enable GuardDuty, so this is the root cause.

  • ✗

    The IAM role for Security Hub does not have permissions to read GuardDuty findings.

    Why it's wrong here

    Security Hub does not use a customer-managed IAM role to read GuardDuty findings. Instead, GuardDuty pushes findings to Security Hub through its integrated service-to-service mechanism. In a multi-account environment, the Security Hub administrator account uses a service-linked role (AWSServiceRoleForSecurityHub) and AWS Organizations to manage member accounts; cross-account permissions are handled automatically when the accounts are part of the expected organization. If GuardDuty is disabled in the member account, there are no findings to send, so the absence of findings is not an IAM permissions problem.

  • ✗

    AWS Config is not enabled in the production account.

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates rules, producing its own kind of findings that Security Hub can aggregate. However, AWS Config is an independent service with no bearing on GuardDuty's ability to generate findings. GuardDuty relies on data sources such as AWS CloudTrail management events, VPC Flow Logs, and DNS logs, not on Config. The lack of AWS Config would not prevent GuardDuty from detecting activity or prevent Security Hub from receiving those findings, so it is not the reason for the missing findings.

  • ✗

    VPC Flow Logs are not enabled in the production account.

    Why it's wrong here

    VPC Flow Logs are one of the data sources GuardDuty consumes for network analysis, but they are not a prerequisite for GuardDuty to produce findings. GuardDuty can still generate findings from other sources like CloudTrail logs and DNS logs, and those findings are sent to Security Hub if GuardDuty is enabled. Moreover, the question is about a complete absence of findings in Security Hub; even if VPC Flow Logs were disabled, GuardDuty would still emit other types of findings. Therefore, VPC Flow Logs being off cannot be the root cause.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.