Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company's incident response team is using AWS Systems Manager to run commands on EC2 instances for forensic analysis. The team needs to ensure that the commands are run with minimal latency and that the results are stored securely. Which Systems Manager capability should the team use?

⚠ Common exam trap

Many candidates confuse Session Manager (interactive access) with Run Command (non-interactive execution), assuming that 'minimal latency' implies a live session, but Run Command is actually faster for scripted tasks because it avoids session setup overhead and can target multiple instances in parallel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager Run Command

AWS Systems Manager Run Command is the correct capability because it allows the incident response team to execute commands on EC2 instances with minimal latency by using the SSM Agent to run scripts or commands directly, and it can store command output in Amazon S3 or CloudWatch Logs for secure, durable storage. This meets the requirement for low-latency execution and secure result storage without requiring interactive sessions or complex automation workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Systems Manager Automation

    Why it's wrong here

    AWS Systems Manager Automation is designed for multi-step operational workflows using runbooks, not for ad-hoc single-command execution. While an Automation document can call Run Command as a step, invoking Automation to run a simple forensic command adds unnecessary orchestration overhead and requires a separate automation IAM role. It also lacks the instantaneous, low-latency direct execution model that incident response teams need when they must dispatch a command and retrieve output immediately.

  • ✗

    AWS Systems Manager Session Manager

    Why it's wrong here

    Session Manager provides an interactive, browser-based shell into a managed instance, requiring a human to initiate and operate the session. Although session activity can be logged to S3, that log is a terminal transcript, not structured command output, and the service does not support unattended, one-to-many command execution. Run Command, in contrast, executes a command across many instances without any interactive login and stores the discrete output in S3 for forensic review.

  • ✗

    AWS Systems Manager Patch Manager

    Why it's wrong here

    Patch Manager is a Systems Manager capability focused exclusively on OS patching tasks, such as scanning for missing patches and applying pre-defined patch baselines. It has no mechanism for running arbitrary incident-response commands or for storing custom command output—it is designed around patch approval rules, not shell-level forensic collection. Consequently, it cannot serve as the vehicle for executing and persisting the output of investigative commands.

  • ✓

    AWS Systems Manager Run Command

    Why this is correct

    AWS Systems Manager Run Command is the correct choice because it executes an arbitrary command (shell or PowerShell) on one or more managed instances through the SSM Agent and can immediately write the output to Amazon S3. It supports tag-based targeting, returns status and response details, and offers low latency—critical for incident response. Storing the output to S3 provides a persistent and auditable record for later analysis, while the same command can be fanned out to a fleet in parallel.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.