A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to ensure that all member accounts send findings to the delegated administrator account. However, some member accounts are not sending findings. What is the most likely cause?
In a GuardDuty multi-account setup, the administrator account sends invitations to member accounts. Each member account must explicitly enable GuardDuty and accept the invitation before it can begin sending findings to the administrator. If a member account has not enabled GuardDuty or has not accepted the invitation, no findings are received from that account. This is the most common reason for missing findings in the administrator console.
Why this answer
GuardDuty requires that each member account has the service explicitly enabled and has accepted the invitation from the delegated administrator account. Without these steps, the member accounts cannot send findings to the administrator, even if AWS Organizations is configured correctly. The delegated administrator can only manage findings from accounts that have completed the onboarding process.
Exam trap
The trap here is that candidates often assume that enabling GuardDuty via AWS Organizations automatically activates it in all member accounts and forwards findings, but in reality, each member account must either accept the invitation or be explicitly enabled by the delegated administrator using the appropriate API call.
How to eliminate wrong answers
Option A is wrong because the GuardDuty service-linked role (AWSServiceRoleForAmazonGuardDuty) is automatically created when GuardDuty is enabled in an account; its absence is a symptom of GuardDuty not being enabled, not a separate cause. Option B is wrong because AWS CloudTrail is a data source for GuardDuty but is not required for findings to be sent; GuardDuty can still generate findings from VPC Flow Logs and DNS logs even if CloudTrail is disabled. Option D is wrong because VPC Flow Logs are another optional data source; GuardDuty can still send findings based on other threat detection feeds without VPC Flow Logs being enabled.