SCS-C02 Threat Detection and Incident Response Practice Question
A company's security team is designing an incident response plan for AWS resources. They want to ensure that when a security incident is detected in a production account, a pre-defined runbook is executed automatically. The runbook includes steps to isolate the compromised resource and collect forensic evidence. Which combination of services should the team use to implement this automation?
⚠ Common exam trap
It's easy for candidates to choose EventBridge and Lambda (Option A) because they are familiar with event-driven automation, but they overlook that Incident Manager provides the required incident lifecycle, response plans, and pre-built runbook templates specifically designed for security incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Systems Manager Incident Manager and AWS Systems Manager Automation
AWS Systems Manager Incident Manager provides the incident management lifecycle, including automated response plans that trigger runbooks when an incident is detected. AWS Systems Manager Automation runbooks contain predefined steps (e.g., isolating EC2 instances, capturing memory dumps, and collecting logs) that can be executed automatically. This combination directly meets the requirement for a pre-defined runbook that isolates the compromised resource and collects forensic evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon EventBridge and AWS Lambda
Why it's wrong here
Amazon EventBridge acts as an event router that can invoke AWS Lambda functions in response to API calls or alarm states, but it provides no built-in incident record, response plan, escalation policy, or post-incident review. While you could technically trigger a Lambda function to perform a recovery action, this pair lacks the structured runbook and engagement capabilities required for a security incident response workflow. You would essentially be assembling point-to-point automation without a coherent incident management framework.
- ✗
AWS Config and Amazon EC2 Auto Scaling
Why it's wrong here
AWS Config continuously monitors and records AWS resource configurations and can evaluate them against compliance rules, while Amazon EC2 Auto Scaling only adjusts instance fleets based on load or health checks. Neither service handles incident detection, severity classification, responder notification, or step-by-step remediation coordination. Although Config can trigger automatic remediation through Systems Manager, this combination does not itself manage the incident lifecycle or provide an operational runbook for security analysts.
- ✗
AWS Step Functions and AWS Lambda
Why it's wrong here
AWS Step Functions can model a workflow as a state machine and invoke AWS Lambda functions for custom logic, so you could hand-build a runbook as orchestrating code. However, it is a general-purpose workflow service, not a security incident management product, meaning you would need to custom-build features such as escalation, on-call scheduling, chat integration, holding pages, and audit trails from scratch. This approach lacks the prebuilt incident response concepts and integrations that come with Incident Manager, making it slower to deploy and more cumbersome to maintain.
- ✓
AWS Systems Manager Incident Manager and AWS Systems Manager Automation
Why this is correct
AWS Systems Manager Incident Manager is purpose-built to manage the full incident lifecycle—it creates an incident record, routes notifications to on-call responders, aggregates related findings, and provides a status page. Systems Manager Automation publishes runbooks (SSM documents) that can perform defined remediation steps, such as isolating an EC2 instance or revoking IAM permissions, either automatically for pre-approved actions or with manual approval. Together they give a security team a closed-loop incident response capability that can reduce mean time to respond and maintain a post-incident audit trail.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.