Courseiva
Threat Detection and Incident ResponsehardMultiple ChoiceObjective-mapped

Why GuardDuty Findings Are Not Displaying in Security Hub from Member Accounts and How to Fix It

A company uses a multi-account AWS Organizations setup with hundreds of accounts. The security team uses AWS Security Hub in the management account to aggregate findings from all accounts. They have configured Amazon GuardDuty in all accounts and enabled AWS Config with recording. Recently, they noticed that Security Hub is not displaying any findings from GuardDuty in member accounts, even though GuardDuty is generating sample findings. The security team has verified that the Security Hub integration with GuardDuty is enabled in the management account. What is the most likely reason for the missing findings?

Quick Answer

The reason findings are missing is that Security Hub's ability to ingest GuardDuty findings is controlled independently in each account, not inherited from the management account. Enabling the Security Hub-GuardDuty integration in the management account only affects the management account's own findings; it does not push that setting down to member accounts, so each member account needs to explicitly turn on the integration between GuardDuty and Security Hub before its findings will flow up into the aggregated view. This is a common pattern in AWS Organizations-based security tooling: many integrations are per-account settings that must be enabled account by account, rather than automatically cascading down from the management account just because the parent service is aggregating data there. Since GuardDuty is confirmed to be actively generating sample findings, and the Security Hub aggregation itself is confirmed to be enabled at the top level, the missing piece has to be a configuration step that lives at the member-account layer rather than a broken pipeline or a misconfigured aggregation region. Whenever a multi-account AWS troubleshooting scenario describes a central console showing data from some accounts but not others, and confirms that both the source service and the central aggregator are functioning, suspect a per-account enablement setting that was never turned on individually in the accounts reporting no data.

⚠ Common exam trap

Many exam-takers assume enabling the integration in the management account automatically propagates to all member accounts, but AWS requires each member account to explicitly enable the GuardDuty-to-SecurityHub integration for findings to be forwarded.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The member accounts have not enabled the integration between GuardDuty and Security Hub.

In a multi-account AWS Organizations setup, Security Hub in the management account aggregates findings from member accounts only if each member account has explicitly enabled the integration between GuardDuty and Security Hub. Even if GuardDuty is generating sample findings in member accounts, Security Hub will not display those findings unless the member account has enabled the GuardDuty-to-SecurityHub integration (via the Security Hub console or API). The management account enabling the integration does not automatically propagate the integration to member accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The IAM role for Security Hub in the management account lacks permissions to read findings from member accounts.

    Why it's wrong here

    The integration uses cross-account roles, but the usual issue is the member-side integration.

  • AWS Security Hub is not enabled in the member accounts.

    Why it's wrong here

    Security Hub in member accounts is not required to forward findings; the integration handles that.

  • Amazon GuardDuty is not enabled in the member accounts.

    Why it's wrong here

    The question states GuardDuty is enabled and generating sample findings.

  • The member accounts have not enabled the integration between GuardDuty and Security Hub.

    Why this is correct

    Each member account must enable the integration to forward findings to Security Hub.

About these practice questions

One of 376 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a multi-account AWS environment using AWS Organizations. The security team uses AWS Security Hub to consolidate findings. They notice that a critical finding in the production account is not being aggregated in Security Hub. The finding is generated by Amazon GuardDuty. What is the MOST likely cause?

hard
  • A.Amazon GuardDuty is not enabled in the production account.
  • B.The IAM role for Security Hub does not have permissions to read GuardDuty findings.
  • C.AWS Config is not enabled in the production account.
  • D.VPC Flow Logs are not enabled in the production account.

Why A: Amazon Security Hub aggregates findings from enabled security services across accounts. For GuardDuty findings to appear in Security Hub, GuardDuty must be enabled in the account where the finding is generated. If GuardDuty is not enabled in the production account, it cannot produce findings for Security Hub to consume, which is the most likely cause of the missing critical finding.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.