Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses Amazon GuardDuty and AWS Security Hub. The security team wants to automatically remediate high-severity GuardDuty findings that indicate an EC2 instance is communicating with a known command and control (C&C) server. The remediation should isolate the instance by modifying the security group to deny all inbound and outbound traffic. Which solution is the most efficient?

⚠ Common exam trap

It's easy for candidates to assume GuardDuty can directly modify security groups (Option C) or that CloudWatch Events can directly perform API actions (Option A), when in reality both require a Lambda function as an intermediary to execute the remediation logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.

It leverages Security Hub as a central aggregation point for GuardDuty findings, then uses EventBridge to trigger a Lambda function that modifies the security group. This is the most efficient architecture as Security Hub normalizes findings from multiple sources, and EventBridge provides reliable, low-latency event routing to Lambda for custom remediation logic without requiring direct GuardDuty-to-security-group integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon CloudWatch Events to directly modify the security group when a GuardDuty finding is published.

    Why it's wrong here

    Amazon CloudWatch Events (now part of Amazon EventBridge) is an event bus service, not a direct API executor. A CloudWatch Events rule can detect a GuardDuty finding and invoke a target, but it cannot itself call the EC2 ModifySecurityGroupIngress or RevokeSecurityGroupIngress APIs. You must attach a Lambda function as the rule's target to perform the security group modification, making the direct-modification claim inaccurate.

  • ✓

    Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.

    Why this is correct

    This is the correct architecture because Security Hub ingests GuardDuty findings as security findings and can forward them to an EventBridge bus. An EventBridge rule can filter for specific finding types or severities and trigger a Lambda function, which then uses the AWS SDK to modify the security group. This decouples detection from remediation and is a standard, supported pattern for automated response to security findings.

  • ✗

    Configure GuardDuty to automatically update the security group when a finding is generated.

    Why it's wrong here

    GuardDuty is a threat detection service, not a remediation service. Its only outputs are finding objects and, optionally, events pushed to EventBridge or CloudWatch Events. GuardDuty has no native ability to modify EC2 security groups or any other AWS resource. Automating a response would require an external compute action—such as a Lambda function—triggered by the finding, so the premise that GuardDuty can directly update a security group is false.

  • ✗

    Create an AWS Config rule that triggers a Lambda function when a security group change is detected.

    Why it's wrong here

    An AWS Config rule that reacts to security group changes is observing the outcome, not the original GuardDuty finding. This approach would only fire after a change has already been made, so it cannot proactively isolate a compromised resource based on the finding. Furthermore, it checks resource configuration compliance rather than the GuardDuty threat signal, so it solves a different problem and fails to address the security finding that initiated the requirement.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.