SCS-C02 Threat Detection and Incident Response Practice Question
A company's incident response team is using AWS Systems Manager to run commands on EC2 instances for forensic analysis. The team needs to ensure that the commands are run with minimal latency and that the results are stored securely. Which Systems Manager capability should the team use?
⚠ Common exam trap
Many candidates confuse Session Manager (interactive access) with Run Command (non-interactive execution), assuming that 'minimal latency' implies a live session, but Run Command is actually faster for scripted tasks because it avoids session setup overhead and can target multiple instances in parallel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Run Command
AWS Systems Manager Run Command is the correct capability because it allows the incident response team to execute commands on EC2 instances with minimal latency by using the SSM Agent to run scripts or commands directly, and it can store command output in Amazon S3 or CloudWatch Logs for secure, durable storage. This meets the requirement for low-latency execution and secure result storage without requiring interactive sessions or complex automation workflows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Systems Manager Automation
Why it's wrong here
AWS Systems Manager Automation is designed for multi-step operational workflows using runbooks, not for ad-hoc single-command execution. While an Automation document can call Run Command as a step, invoking Automation to run a simple forensic command adds unnecessary orchestration overhead and requires a separate automation IAM role. It also lacks the instantaneous, low-latency direct execution model that incident response teams need when they must dispatch a command and retrieve output immediately.
- ✗
AWS Systems Manager Session Manager
Why it's wrong here
Session Manager provides an interactive, browser-based shell into a managed instance, requiring a human to initiate and operate the session. Although session activity can be logged to S3, that log is a terminal transcript, not structured command output, and the service does not support unattended, one-to-many command execution. Run Command, in contrast, executes a command across many instances without any interactive login and stores the discrete output in S3 for forensic review.
- ✗
AWS Systems Manager Patch Manager
Why it's wrong here
Patch Manager is a Systems Manager capability focused exclusively on OS patching tasks, such as scanning for missing patches and applying pre-defined patch baselines. It has no mechanism for running arbitrary incident-response commands or for storing custom command output—it is designed around patch approval rules, not shell-level forensic collection. Consequently, it cannot serve as the vehicle for executing and persisting the output of investigative commands.
- ✓
AWS Systems Manager Run Command
Why this is correct
AWS Systems Manager Run Command is the correct choice because it executes an arbitrary command (shell or PowerShell) on one or more managed instances through the SSM Agent and can immediately write the output to Amazon S3. It supports tag-based targeting, returns status and response details, and offers low latency—critical for incident response. Storing the output to S3 provides a persistent and auditable record for later analysis, while the same command can be fanned out to a fleet in parallel.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.