Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company is using AWS Lambda functions to process sensitive data. The security team wants to detect when a Lambda function is invoked with an unexpected payload that may indicate an injection attack. Which AWS service should the team use to inspect the function's input for malicious patterns?

⚠ Common exam trap

Test-takers frequently assume AWS WAF or GuardDuty can inspect all types of data flowing through AWS, but in reality, these services have specific scope limitations and cannot inspect Lambda invocation payloads directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

None of the above; the team should implement custom validation within the Lambda function.

AWS Lambda functions process event payloads directly within the function code, and no AWS managed service can inspect the actual input data passed to a Lambda function at invocation time. AWS WAF operates at the HTTP/HTTPS layer for API Gateway or CloudFront, not for Lambda function payloads. Amazon Inspector scans for software vulnerabilities in EC2 instances and container images, not runtime payloads. AWS Shield provides DDoS protection at the network and transport layers. Amazon GuardDuty analyzes VPC flow logs, DNS logs, and CloudTrail events for threats, but it does not inspect Lambda function invocation payloads. Therefore, the only way to detect malicious patterns in the function's input is to implement custom validation logic within the Lambda function code itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF operates only on HTTP(S) traffic forwarding through CloudFront, Application Load Balancer, or API Gateway, applying managed or string-match rules to web requests. Direct Lambda invocations—via the SDK, CLI, or async events like S3 or SQS—never traverse WAF, and WAF cannot inspect raw event payloads passed to a Lambda function. Therefore it cannot prevent injection attacks aimed at a Lambda handler.

  • ✓

    None of the above; the team should implement custom validation within the Lambda function.

    Why this is correct

    Lambda does not include a built-in AWS service that intercepts and validates event payloads for injection attacks such as SQL, OS command, or NoSQL injection. The correct approach is to implement custom input validation and sanitization inside the function code—for example using allowlists, parameterized queries, and parsing libraries—because only the function itself understands the expected schema and context of its event data.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans managed resources, including Lambda functions, for software vulnerabilities and unintended network exposure, such as known CVEs in dependencies or overly permissive IAM roles, not for malicious content in runtime event payloads. Injection attacks are a logic- and input-validation issue triggered at invocation time, so Inspector's static, scan-based model cannot detect them in individual invocations.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is designed to mitigate distributed denial-of-service attacks at the network and transport layers, primarily protecting edge resources like CloudFront, Route 53, and Application Load Balancers from volumetric flood traffic. It has no visibility into Lambda function event data, and direct Lambda invocations are not internet-reachable endpoints that Shield can front, so it cannot address payload-level injection attempts.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes telemetry from CloudTrail, VPC Flow Logs, DNS logs, and EKS audit logs to identify suspicious activity like compromised credentials, API abuse, or crypto mining. For Lambda, GuardDuty can detect abnormal behavior by the function's execution role, but it never inspects the content of each event payload passed to the function, so it cannot detect injection attacks embedded in that payload.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.