SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Organizations and wants to implement a centralized incident response process. Which THREE steps should be taken to ensure that security teams can respond to incidents across all accounts effectively?
⚠ Common exam trap
Many exam-takers think a single CloudTrail trail in the management account automatically aggregates logs from all accounts, but without configuring it as an organization trail (which requires enabling trusted access and specifying the organization ID), it only logs events from the management account itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create IAM roles in each member account that grant incident responders cross-account access from the security account
Creating IAM roles in each member account with trust policies that allow the security account's incident responders to assume those roles enables centralized, cross-account access for incident response. This follows the principle of least privilege and allows the security team to perform actions (e.g., stopping instances, collecting forensic data) in any affected account without needing separate credentials or direct logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create IAM roles in each member account that grant incident responders cross-account access from the security account
Why this is correct
Creating IAM roles in each member account that allow incident responders in the security account to assume those roles is a standard centralized access pattern. This grants the responders the exact permissions needed to investigate and remediate incidents in any affected account, while maintaining least privilege and full auditability. It avoids the need for shared credentials or per-account logins, and ensures that every cross-account assumption is recorded in CloudTrail for accountability.
- ✗
Set up AWS Systems Manager Incident Manager in each account independently
Why it's wrong here
Setting up AWS Systems Manager Incident Manager in each account independently creates siloed incident management, where each account has its own contacts, escalation plans, and incident timelines. This makes it difficult for a central security team to get a unified view of an incident that spans multiple accounts, leading to duplicated effort and inconsistent response procedures. With no centralized incident dashboard, there is no single source of truth for incident status and coordination.
- ✗
Create a single CloudTrail trail in the management account to log events from all accounts
Why it's wrong here
Creating a single CloudTrail trail in the management account to log events from all accounts is a common misconception; a standard trail in the management account only logs events for that management account itself. To capture activity from every member account, you must configure an organization trail, which automatically covers all accounts in the organization and delivers their logs to a centralized destination. A plain management-account trail has no visibility into event activity occurring inside the member accounts.
- ✓
Configure a centralized S3 bucket to store CloudTrail logs from all accounts using an organization trail
Why this is correct
Configuring a centralized S3 bucket to store CloudTrail logs from all accounts using an organization trail gives the security team a complete and immutable audit log across the entire organization. By delivering logs from every account to a single bucket that only the security account can access, the team can efficiently run cross-account log analysis and detect anomalies spanning multiple accounts. This also prevents member account administrators from altering or deleting their own CloudTrail logs, preserving the integrity of evidence needed for incident response.
- ✓
Designate a delegated administrator account for Amazon GuardDuty to centralize threat detection findings
Why this is correct
Designating a delegated administrator account for Amazon GuardDuty centralizes the management and visibility of threat detection findings across the organization. The security account can then enable GuardDuty on all member accounts, manage detectors centrally, and view aggregated findings from a single pane of glass. This consolidated view enables incident responders to rapidly triage and correlate threats across accounts, which is crucial for detecting and remediating multi-stage attacks that cross account boundaries.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.