Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company's security team uses AWS Security Hub in a central security account. They want to ensure that when a critical finding is generated in any member account, the affected resource is automatically tagged with an incident identifier and the finding is routed to a third-party ticketing system. Which approach best meets these requirements?

⚠ Common exam trap

The trap here is expecting cross-region aggregation in Security Hub to also forward EventBridge events, when aggregation only consolidates findings for viewing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.

Security Hub publishes findings to EventBridge in the account where they are generated, so a rule in each member account can match critical severity and invoke a Lambda function that tags the resource and creates a ticket. This provides automatic, near real-time response in every account without manual intervention, and it scales across an organization when deployed consistently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config conformance packs to evaluate resources, and configure an Amazon SNS topic that invokes the tagging and ticketing Lambda function for noncompliant resources.

    Why it's wrong here

    AWS Config conformance packs evaluate resource compliance against rules; they do not consume Security Hub findings or route them to a ticketing system. SNS delivers messages to subscribers but does not directly invoke Lambda based on a finding, and this approach does not tag resources based on critical findings.

  • ✓

    Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.

    Why this is correct

    Security Hub automatically sends all findings to EventBridge in the account where the finding is generated. An EventBridge rule matching ImportFindings or the severity field can invoke a Lambda function that applies the incident tag and integrates with the ticketing system, providing automatic response in every member account.

  • ✗

    Create a custom action in Security Hub that the analyst manually triggers for each critical finding, and configure the custom action to invoke a Lambda function that tags the resource and creates a ticket.

    Why it's wrong here

    Custom actions require manual invocation by an analyst, so they do not provide automatic tagging or routing when a critical finding is generated. This adds human latency and does not meet the requirement for automatic response to every critical finding across member accounts.

  • ✗

    Enable cross-region aggregation in Security Hub and configure a single EventBridge rule in the aggregation Region to invoke the tagging and ticketing Lambda function for all findings.

    Why it's wrong here

    Cross-region aggregation consolidates findings for viewing and reporting, but EventBridge rules in the aggregation Region do not receive events for findings generated in other Regions or accounts. The tagging Lambda would not be invoked for findings in member accounts, so automation would not occur.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.