Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company is using Amazon GuardDuty to monitor for malicious activity. The security team wants to automatically isolate an EC2 instance that is flagged for outbound communication with a known malicious IP address. Which approach is the most efficient and scalable?

⚠ Common exam trap

It's easy for candidates to confuse CloudWatch Alarms with EventBridge rules, not realizing that EventBridge provides native, real-time event filtering and direct Lambda invocation without the polling or metric-based delays inherent in CloudWatch Alarms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.

Amazon EventBridge can directly capture GuardDuty findings as events and trigger an AWS Lambda function to modify the instance's security group, revoking outbound access to the malicious IP. This approach is event-driven, serverless, and scales automatically without polling or manual intervention, making it the most efficient and scalable solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a CloudWatch Alarm to directly invoke a Lambda function to isolate the instance.

    Why it's wrong here

    CloudWatch Alarms do not support Lambda as a direct action target—the only action types are SNS, EC2 stop/terminate/reboot, Auto Scaling, and OpsItems. To invoke Lambda you would have to route the alarm through an SNS topic, adding an extra hop and potential delay. Moreover, an alarm-based action cannot dynamically identify the specific security group to change, so it fails to provide the precise, reversible containment needed for a GuardDuty finding.

  • ✗

    Use AWS Config to automatically terminate the instance when a GuardDuty finding is reported.

    Why it's wrong here

    AWS Config is fundamentally a resource configuration auditing service, not a security finding event processor; it evaluates your resources against compliance rules and can run automatic remediation via SSM documents, but it has no native integration that reacts to the GuardDuty finding event stream. Forcing it to terminate an instance would be a destructive, irreversible action that destroys volatile forensic data and halts the workload, even for a potentially false positive. An effective isolation response should preserve the instance for investigation while cutting only its malicious network path.

  • ✓

    Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.

    Why this is correct

    GuardDuty publishes every finding as an event to Amazon EventBridge, where a rule with an event pattern matching specific finding types and severities can route to a Lambda function. That function can call ec2:RevokeSecurityGroupIngress or ec2:ModifyNetworkInterfaceAttribute to swap the instance onto a dedicated quarantine security group, removing internet-facing ingress rules. This approach is targeted to the exact resource in the finding, reversible, and scales across many findings without affecting the rest of the subnet.

  • ✗

    Create a CloudWatch alarm on GuardDuty findings and modify the subnet's network ACL to block the traffic.

    Why it's wrong here

    GuardDuty findings are emitted as events to EventBridge, not as CloudWatch metrics, so a CloudWatch alarm cannot natively consume them; you would need an intermediate event rule and a custom metric publisher, which is convoluted and unreliable. Even if you implemented that, a subnet network ACL is stateless and applies to every instance in the subnet, so blocking the traffic would also take down unrelated, legitimate workloads. Security groups, by contrast, are stateful and attach directly to the instance's elastic network interface, making them the correct layer for per-instance quarantine.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.