SCS-C02 Threat Detection and Incident Response Practice Question
A company's security team uses AWS Security Hub in a central security account. They want to ensure that when a critical finding is generated in any member account, the affected resource is automatically tagged with an incident identifier and the finding is routed to a third-party ticketing system. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is expecting cross-region aggregation in Security Hub to also forward EventBridge events, when aggregation only consolidates findings for viewing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.
Security Hub publishes findings to EventBridge in the account where they are generated, so a rule in each member account can match critical severity and invoke a Lambda function that tags the resource and creates a ticket. This provides automatic, near real-time response in every account without manual intervention, and it scales across an organization when deployed consistently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config conformance packs to evaluate resources, and configure an Amazon SNS topic that invokes the tagging and ticketing Lambda function for noncompliant resources.
Why it's wrong here
AWS Config conformance packs evaluate resource compliance against rules; they do not consume Security Hub findings or route them to a ticketing system. SNS delivers messages to subscribers but does not directly invoke Lambda based on a finding, and this approach does not tag resources based on critical findings.
- ✓
Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.
Why this is correct
Security Hub automatically sends all findings to EventBridge in the account where the finding is generated. An EventBridge rule matching ImportFindings or the severity field can invoke a Lambda function that applies the incident tag and integrates with the ticketing system, providing automatic response in every member account.
- ✗
Create a custom action in Security Hub that the analyst manually triggers for each critical finding, and configure the custom action to invoke a Lambda function that tags the resource and creates a ticket.
Why it's wrong here
Custom actions require manual invocation by an analyst, so they do not provide automatic tagging or routing when a critical finding is generated. This adds human latency and does not meet the requirement for automatic response to every critical finding across member accounts.
- ✗
Enable cross-region aggregation in Security Hub and configure a single EventBridge rule in the aggregation Region to invoke the tagging and ticketing Lambda function for all findings.
Why it's wrong here
Cross-region aggregation consolidates findings for viewing and reporting, but EventBridge rules in the aggregation Region do not receive events for findings generated in other Regions or accounts. The tagging Lambda would not be invoked for findings in member accounts, so automation would not occur.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.