DOP-C02 Incident and Event Response Practice Question
A company has a multi-account AWS organization. The security team needs to detect and respond to security incidents across all accounts centrally. Which THREE services should the team use together? (Choose three.)
⚠ Common exam trap
DOP-C02 often tests the distinction between detection/aggregation/investigation services (GuardDuty, Security Hub, Detective) and specialized scanning services (Inspector for vulnerabilities, Macie for sensitive data) — candidates include Inspector or Macie thinking 'security' means all of them, but the question asks for the central detection-and-response trio.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub (A) is correct because it acts as the central aggregation and prioritization layer, ingesting findings from GuardDuty, Inspector, Macie, and other services across all accounts in the organization and normalizing them to the AWS Security Finding Format (ASFF) for a single-pane-of-glass view. Amazon GuardDuty (D) is correct because it provides the continuous threat detection foundation, analyzing CloudTrail management events, VPC Flow Logs, and DNS logs across every account to surface malicious or unauthorized activity. Amazon Detective (E) is correct because it complements detection with investigation, automatically building behavior graphs from GuardDuty, CloudTrail, and VPC Flow Logs so the security team can triage and root-cause incidents centrally. Amazon Inspector (B) is not one of the three because it is a vulnerability management service scoped to EC2, ECR, and Lambda resources rather than a cross-account incident detection and response hub. Amazon Macie (C) is not one of the three because it is a data-security service that discovers and classifies sensitive data in S3, which is useful but not part of the core centralized detect-and-respond trio.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub is the correct answer because it is designed as a multi-account, multi-region aggregation service that centralizes security findings from AWS services and partner products. It enables a delegated administrator to view a consolidated security posture across the entire AWS Organizations hierarchy, evaluate compliance against standards like CIS and NIST, and automate responses via custom actions and AWS Config rules.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that scans compute workloads (EC2 instances, ECR images, and Lambda functions) for software vulnerabilities and unintended network exposure. It generates its own findings but lacks the ability to aggregate findings from other security services across multiple accounts, so it is a telemetry source consumed by Security Hub rather than the central view itself.
- ✗
Amazon Macie
Why it's wrong here
Amazon Macie uses machine learning and pattern matching to discover and classify sensitive data, such as personally identifiable information (PII) or credentials, stored in Amazon S3 buckets. It produces data classification and policy findings, but its scope is limited to data security and privacy, not cross-account security orchestration; it reports into Security Hub for central visibility rather than serving as the consolidated view.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, DNS query logs, CloudTrail management and data events, and S3 data events to identify malicious activity across all member accounts in an organization. While it supplies high-value findings to Security Hub, it cannot aggregate findings from Inspector, Macie, or other tools, so it is not the central aggregation point the security team requires.
- ✓
Amazon Detective
Why this is correct
Amazon Detective is a post-incident investigation service that ingests enrichments from GuardDuty findings, VPC Flow Logs, CloudTrail, and EKS audit logs to build interactive graphs of resources and identities. Its purpose is root-cause analysis and forensic correlation during a security investigation, not to provide a continuous multi-account compliance dashboard or consolidated finding aggregator, so it complements Security Hub rather than replacing it.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.