Courseiva
Incident ResponsemediumMultiple SelectObjective-mapped

SCS-C03 Incident Response Practice Question

An organization wants to improve their ability to respond to security incidents. Which TWO of the following services provide centralized visibility and management for security findings?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Security Hub

AWS Security Hub and Amazon Detective are designed to aggregate, manage, and investigate security data. Security Hub acts as the central pane of glass for findings from various AWS services, while Detective provides the visualization tools needed to investigate the root cause of those findings. Together, they streamline the identification and triage process, allowing responders to move quickly from alert to conclusion during a security incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Security Hub

    Why this is correct

    Security Hub aggregates security findings from across AWS services and partner products into a single location. It provides a centralized view of an organization's security posture and compliance status, which is vital for prioritizing and managing incident response workflows during a security event.

  • Amazon Detective

    Why this is correct

    Amazon Detective simplifies the investigative process by automatically collecting and correlating data from CloudTrail, VPC Flow Logs, and GuardDuty. It provides a visual representation of relationships between resources and IP addresses, helping responders quickly identify the scope and nature of security incidents.

  • Amazon CloudWatch

    Why it's wrong here

    CloudWatch is primarily for monitoring metrics, logs, and performance data. While it can be used to set up alarms for security events, it lacks the specialized correlation, finding aggregation, and forensic visualization capabilities that are required for centralized security incident management and deep root-cause investigation.

  • AWS Artifact

    Why it's wrong here

    AWS Artifact provides on-demand access to AWS security and compliance reports, such as ISO certifications and SOC reports. It is not an incident response tool and does not provide visibility into active security alerts or findings related to an organization's internal infrastructure and operations.

  • AWS Systems Manager

    Why it's wrong here

    Systems Manager is an operations management tool used for configuration, patching, and task automation. While it can be used for remediation, it is not a tool for aggregating security findings or providing the investigative visualization required for incident response and threat analysis.

About these practice questions

Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.