SCS-C02 Threat Detection and Incident Response Practice Question
A company uses Amazon GuardDuty and AWS Security Hub. The security team wants to automatically remediate high-severity GuardDuty findings that indicate an EC2 instance is communicating with a known command and control (C&C) server. The remediation should isolate the instance by modifying the security group to deny all inbound and outbound traffic. Which solution is the most efficient?
⚠ Common exam trap
It's easy for candidates to assume GuardDuty can directly modify security groups (Option C) or that CloudWatch Events can directly perform API actions (Option A), when in reality both require a Lambda function as an intermediary to execute the remediation logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.
It leverages Security Hub as a central aggregation point for GuardDuty findings, then uses EventBridge to trigger a Lambda function that modifies the security group. This is the most efficient architecture as Security Hub normalizes findings from multiple sources, and EventBridge provides reliable, low-latency event routing to Lambda for custom remediation logic without requiring direct GuardDuty-to-security-group integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon CloudWatch Events to directly modify the security group when a GuardDuty finding is published.
Why it's wrong here
Amazon CloudWatch Events (now part of Amazon EventBridge) is an event bus service, not a direct API executor. A CloudWatch Events rule can detect a GuardDuty finding and invoke a target, but it cannot itself call the EC2 ModifySecurityGroupIngress or RevokeSecurityGroupIngress APIs. You must attach a Lambda function as the rule's target to perform the security group modification, making the direct-modification claim inaccurate.
- ✓
Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.
Why this is correct
This is the correct architecture because Security Hub ingests GuardDuty findings as security findings and can forward them to an EventBridge bus. An EventBridge rule can filter for specific finding types or severities and trigger a Lambda function, which then uses the AWS SDK to modify the security group. This decouples detection from remediation and is a standard, supported pattern for automated response to security findings.
- ✗
Configure GuardDuty to automatically update the security group when a finding is generated.
Why it's wrong here
GuardDuty is a threat detection service, not a remediation service. Its only outputs are finding objects and, optionally, events pushed to EventBridge or CloudWatch Events. GuardDuty has no native ability to modify EC2 security groups or any other AWS resource. Automating a response would require an external compute action—such as a Lambda function—triggered by the finding, so the premise that GuardDuty can directly update a security group is false.
- ✗
Create an AWS Config rule that triggers a Lambda function when a security group change is detected.
Why it's wrong here
An AWS Config rule that reacts to security group changes is observing the outcome, not the original GuardDuty finding. This approach would only fire after a change has already been made, so it cannot proactively isolate a compromised resource based on the finding. Furthermore, it checks resource configuration compliance rather than the GuardDuty threat signal, so it solves a different problem and fails to address the security finding that initiated the requirement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.