SCS-C02 Security Logging and Monitoring Practice Question
A company is using Amazon GuardDuty to monitor for malicious activity. The security team wants to automatically isolate an EC2 instance that is flagged for outbound communication with a known malicious IP address. Which approach is the most efficient and scalable?
⚠ Common exam trap
It's easy for candidates to confuse CloudWatch Alarms with EventBridge rules, not realizing that EventBridge provides native, real-time event filtering and direct Lambda invocation without the polling or metric-based delays inherent in CloudWatch Alarms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.
Amazon EventBridge can directly capture GuardDuty findings as events and trigger an AWS Lambda function to modify the instance's security group, revoking outbound access to the malicious IP. This approach is event-driven, serverless, and scales automatically without polling or manual intervention, making it the most efficient and scalable solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a CloudWatch Alarm to directly invoke a Lambda function to isolate the instance.
Why it's wrong here
CloudWatch Alarms do not support Lambda as a direct action target—the only action types are SNS, EC2 stop/terminate/reboot, Auto Scaling, and OpsItems. To invoke Lambda you would have to route the alarm through an SNS topic, adding an extra hop and potential delay. Moreover, an alarm-based action cannot dynamically identify the specific security group to change, so it fails to provide the precise, reversible containment needed for a GuardDuty finding.
- ✗
Use AWS Config to automatically terminate the instance when a GuardDuty finding is reported.
Why it's wrong here
AWS Config is fundamentally a resource configuration auditing service, not a security finding event processor; it evaluates your resources against compliance rules and can run automatic remediation via SSM documents, but it has no native integration that reacts to the GuardDuty finding event stream. Forcing it to terminate an instance would be a destructive, irreversible action that destroys volatile forensic data and halts the workload, even for a potentially false positive. An effective isolation response should preserve the instance for investigation while cutting only its malicious network path.
- ✓
Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.
Why this is correct
GuardDuty publishes every finding as an event to Amazon EventBridge, where a rule with an event pattern matching specific finding types and severities can route to a Lambda function. That function can call ec2:RevokeSecurityGroupIngress or ec2:ModifyNetworkInterfaceAttribute to swap the instance onto a dedicated quarantine security group, removing internet-facing ingress rules. This approach is targeted to the exact resource in the finding, reversible, and scales across many findings without affecting the rest of the subnet.
- ✗
Create a CloudWatch alarm on GuardDuty findings and modify the subnet's network ACL to block the traffic.
Why it's wrong here
GuardDuty findings are emitted as events to EventBridge, not as CloudWatch metrics, so a CloudWatch alarm cannot natively consume them; you would need an intermediate event rule and a custom metric publisher, which is convoluted and unreliable. Even if you implemented that, a subnet network ACL is stateless and applies to every instance in the subnet, so blocking the traffic would also take down unrelated, legitimate workloads. Security groups, by contrast, are stateful and attach directly to the instance's elastic network interface, making them the correct layer for per-instance quarantine.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.