Courseiva
Knowledge + Practice
CertificationsVendorsCareer RoadmapsLabs & ToolsStudy GuidesGlossaryPractice Questions
C
Courseiva

Free IT certification practice questions with explained answers for CCNA, CompTIA, AWS, Azure, Google Cloud, and more.

Certification Practice Questions

CCNA practice questionsSecurity+ SY0-701 practice questionsAWS SAA-C03 practice questionsAZ-104 practice questionsAZ-900 practice questionsCLF-C02 practice questionsA+ Core 1 practice questionsGoogle Cloud ACE practice questionsCySA+ CS0-003 practice questionsNetwork+ N10-009 practice questions
View all certifications →

Product

CertificationsCertification PathsExam TopicsPractice TestsExam Dumps vs Practice TestsStudy HubComparisons

Company

AboutContactEditorial PolicyQuestion Writing PolicyTrust Center

Legal

Privacy PolicyTerms of Service

Courseiva is a free IT certification practice platform offering original exam-style practice questions, detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics for Cisco, CompTIA, Microsoft, AWS, and other technology certifications.

© 2026 Courseiva. Courseiva is operated by JTNetSolutions Ltd. All rights reserved.

Courseiva is an independent certification practice platform and is not affiliated with, endorsed by, or sponsored by Cisco, Microsoft, AWS, CompTIA, Google, ISC2, ISACA, or any other certification vendor. Vendor names and certification marks are used only to identify the exams learners are preparing for.

HomeCertificationsSCS-C02TopicsThreat Detection and Incident Response
Free · No Signup RequiredAmazon Web Services · SCS-C02

SCS-C02 Threat Detection and Incident Response Practice Questions

20+ practice questions focused on Threat Detection and Incident Response — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.

Start Threat Detection and Incident Response Practice

Exam Domains

Threat Detection and Incident ResponseSecurity Logging and MonitoringIdentity and Access ManagementManagement and Security GovernanceInfrastructure SecurityData ProtectionAll domains →

Study Tools

Practice TestMock ExamFlashcardsAll Topics

Sample Threat Detection and Incident Response Questions

Practice all 20+ →
1.

A security engineer is configuring an AWS environment to detect and respond to potential security threats. Which AWS service can be used to automate the remediation of unwanted access to Amazon S3 buckets by invoking AWS Lambda functions?

A.AWS Config
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS WAF

Explanation: Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It can integrate with AWS Lambda functions via CloudWatch Events to automate remediation actions, such as blocking unwanted access to S3 buckets by updating bucket policies or removing public access. This makes GuardDuty the correct choice for detecting and automatically responding to security threats against S3 resources.

2.

A security team suspects that an attacker has compromised an EC2 instance and is using it to launch outbound DDoS attacks. The team needs to quickly isolate the instance while preserving forensic data. Which combination of actions should the team take? (Choose TWO.)

A.Apply a restrictive security group that blocks all outbound traffic.
B.Modify the network ACL for the subnet to deny all outbound traffic.
C.Create a snapshot of the EBS volumes attached to the EC2 instance.
D.Detach the instance from the Auto Scaling group.

Explanation: Option A is correct because applying a restrictive security group that blocks all outbound traffic immediately stops the EC2 instance from sending any network packets, including DDoS traffic, without terminating the instance. This preserves the running state and allows forensic data collection from the instance's memory and disk. Security groups act as a stateful virtual firewall at the instance level, so blocking outbound traffic effectively isolates the instance from the network.

3.

During an incident response, a security engineer needs to collect memory and disk forensics from a running EC2 Windows instance without causing the instance to crash. The engineer has AWS Systems Manager SSM Agent installed. Which method should the engineer use?

A.Create an AMI of the instance.
B.Use AWS Systems Manager Inventory to collect memory and disk information.
C.Use AWS Backup to create a backup of the instance.
D.Create an EBS snapshot of the root volume.

Explanation: Option B is correct because AWS Systems Manager Inventory can collect both memory and disk forensics from a running EC2 Windows instance without causing it to crash. The SSM Agent, already installed, allows Inventory to gather metadata such as running processes (memory) and file system details (disk) via the AWS-CollectInventory document, which is designed for live data collection without rebooting or halting the instance.

4.

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)

A.Amazon GuardDuty with threat detection enabled.
B.AWS Config with recording enabled for all resources.
C.Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
D.VPC Flow Logs for all VPCs.

Explanation: Option C is correct because an Amazon S3 lifecycle policy can automatically transition CloudTrail log objects from S3 Standard to S3 Glacier after one year, meeting the retention requirement cost-effectively. Option E is correct because AWS CloudTrail with an organization trail logs all API calls across all accounts in the AWS Organization, ensuring comprehensive logging.

5.

A security engineer is investigating a potential data exfiltration incident. The engineer notices large volumes of data being transferred from an Amazon S3 bucket to an external IP address. Which AWS services can be used to detect and alert on such behavior? (Choose THREE.)

A.Amazon CloudWatch Logs with S3 access log analysis.
B.AWS CloudTrail with S3 data event logging.
C.Amazon GuardDuty with anomaly detection.
D.AWS Config with compliance rules.

Explanation: Amazon CloudWatch Logs can ingest and analyze S3 access logs, which record detailed information about requests made to an S3 bucket, including the source IP address, request type, and bytes transferred. By analyzing these logs with CloudWatch Logs Insights or metric filters, you can detect large data transfers to external IPs and trigger alerts via CloudWatch Alarms, making it a valid detection and alerting mechanism for data exfiltration.

+15 more Threat Detection and Incident Response questions available

Practice all Threat Detection and Incident Response questions

How to master Threat Detection and Incident Response for SCS-C02

1. Baseline your knowledge

Start with 10 questions to gauge your current understanding of Threat Detection and Incident Response. This tells you whether you need a concept refresher or just practice.

2. Review every explanation

For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.

3. Focus on exam traps

Threat Detection and Incident Response questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.

4. Reach 80% consistently

Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.

Frequently asked questions

How many SCS-C02 Threat Detection and Incident Response questions are on the real exam?

The exact number varies per candidate. Threat Detection and Incident Response is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Threat Detection and Incident Response questions ensures you can handle any format or difficulty that appears.

Are these SCS-C02 Threat Detection and Incident Response practice questions free?

Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.

Is Threat Detection and Incident Response one of the harder SCS-C02 topics?

Difficulty is subjective, but Threat Detection and Incident Response is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.

Ready to practice?

Launch a full Threat Detection and Incident Response practice session with instant scoring and detailed explanations.

Start Threat Detection and Incident Response Practice →

Topic Info

Topic

Threat Detection and Incident Response

Exam

SCS-C02

Questions available

20+