Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company has an AWS Lambda function that processes sensitive data. The security team wants to ensure that any errors or suspicious behavior are immediately investigated. Which combination of services should be used to send real-time notifications for anomalous function executions?

⚠ Common exam trap

Watch out — candidates often confuse CloudTrail (which logs API calls) with CloudWatch Logs (which captures application-level execution output), leading them to choose CloudTrail for real-time error monitoring when it is actually designed for auditing and compliance, not for triggering on application errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudWatch Logs and SNS

CloudWatch Logs can capture Lambda function execution logs, and a CloudWatch Logs metric filter can be configured to detect patterns indicative of errors or suspicious behavior (e.g., 'ERROR', 'Exception', or custom anomaly patterns). When the metric filter triggers a CloudWatch alarm, it can publish a message directly to an Amazon SNS topic, which then sends real-time notifications (e.g., email, SMS, or HTTP endpoint) to the security team for immediate investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CloudWatch Logs and SNS

    Why this is correct

    Lambda function execution output is written to CloudWatch Logs, so a metric filter can parse log events for patterns such as 'ERROR' or 'AccessDenied' and drive a CloudWatch alarm. The alarm then publishes to an SNS topic, delivering real-time notifications to operators. This is the native, low-latency monitoring path for Lambda function behavior and is ideal for sensitive-data processing failures.

  • ✗

    CloudTrail and SNS

    Why it's wrong here

    CloudTrail records management and data-plane API calls made by or on behalf of the Lambda function, such as Invoke, CreateFunction, or policy changes, but it does not capture the function's stdout/stderr, runtime exceptions, or custom application logs. Therefore SNS alerts triggered by CloudTrail events would not indicate processing errors or anomalous execution of the function. It is useful for audit trail analysis, not real-time application-level log monitoring.

  • ✗

    AWS Config and SQS

    Why it's wrong here

    AWS Config evaluates resource configurations, such as whether the Lambda function's environment variables are encrypted or its IAM role is compliant, and can deliver configuration snapshots or compliance changes via SNS, but it cannot inspect log output or runtime errors. SQS is a message queue, not a notification destination, and Config would only trigger on resource configuration changes, not on sensitive data processing failures. Hence this combination is unsuitable for real-time alerting on function execution.

  • ✗

    Amazon Detective and SES

    Why it's wrong here

    Amazon Detective ingests findings from GuardDuty, CloudTrail, VPC Flow Logs, and EKS and builds behavior graphs for post-incident security investigations; it does not continuously monitor CloudWatch Logs from a Lambda function or generate real-time operational alerts. SES is an email-sending service and could theoretically deliver an alert, but Detective does not emit event notifications when application logs contain an error. This combination is designed for forensic analysis after a security event, not for immediate processing-failure alerts.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.