SCS-C03 Incident Response Practice Question
An organization wants to improve their ability to respond to security incidents. Which TWO of the following services provide centralized visibility and management for security findings?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub and Amazon Detective are designed to aggregate, manage, and investigate security data. Security Hub acts as the central pane of glass for findings from various AWS services, while Detective provides the visualization tools needed to investigate the root cause of those findings. Together, they streamline the identification and triage process, allowing responders to move quickly from alert to conclusion during a security incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Security Hub
Why this is correct
Security Hub aggregates security findings from across AWS services and partner products into a single location. It provides a centralized view of an organization's security posture and compliance status, which is vital for prioritizing and managing incident response workflows during a security event.
- ✓
Amazon Detective
Why this is correct
Amazon Detective simplifies the investigative process by automatically collecting and correlating data from CloudTrail, VPC Flow Logs, and GuardDuty. It provides a visual representation of relationships between resources and IP addresses, helping responders quickly identify the scope and nature of security incidents.
- ✗
Amazon CloudWatch
Why it's wrong here
CloudWatch is primarily for monitoring metrics, logs, and performance data. While it can be used to set up alarms for security events, it lacks the specialized correlation, finding aggregation, and forensic visualization capabilities that are required for centralized security incident management and deep root-cause investigation.
- ✗
AWS Artifact
Why it's wrong here
AWS Artifact provides on-demand access to AWS security and compliance reports, such as ISO certifications and SOC reports. It is not an incident response tool and does not provide visibility into active security alerts or findings related to an organization's internal infrastructure and operations.
- ✗
AWS Systems Manager
Why it's wrong here
Systems Manager is an operations management tool used for configuration, patching, and task automation. While it can be used for remediation, it is not a tool for aggregating security findings or providing the investigative visualization required for incident response and threat analysis.
About these practice questions
Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.