Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Organizations with multiple accounts and has enabled AWS Security Hub in the management account. The security team wants to automatically remediate a specific finding type that appears in Security Hub. Which combination of services should be used to achieve this?

⚠ Common exam trap

Many exam-takers confuse Security Hub's integration with other AWS security services (GuardDuty, Inspector) as the trigger mechanism, when in fact EventBridge is the standardized event bus that Security Hub uses to emit findings for automated response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon EventBridge and AWS Lambda

Amazon EventBridge can capture Security Hub findings as events using an event rule that matches the specific finding type. When the rule triggers, it invokes an AWS Lambda function that contains the remediation logic, such as modifying security group rules or disabling access keys. This combination provides a serverless, event-driven architecture for automated response to Security Hub findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon EventBridge and AWS Lambda

    Why this is correct

    Security Hub natively publishes findings to an Amazon EventBridge default event bus, so a rule in the administrator account can match the source 'aws.securityhub' and invoke a Lambda function for immediate remediation. The Lambda function can parse the finding ID, AwsAccountId, and compliance status, then execute corrective action such as modifying an IAM policy or enabling encryption. In a multi-account organization, this is the intended native path for turning Security Hub findings into automated responses, especially when cross-Region aggregation is enabled.

  • ✗

    AWS Config conformance packs and AWS Systems Manager Automation

    Why it's wrong here

    AWS Config conformance packs consist of collections of Config rules and remediation actions that continuously evaluate resource configuration, and Systems Manager Automation documents can then fix resources that drift from compliance. However, Config does not subscribe to or react directly to Security Hub findings—it tracks configuration changes against its own rules, not the consolidated security findings aggregated by Security Hub. As a result, this combination would not automatically process Security Hub finding events unless you first build a custom EventBridge connector to translate those findings into Config rule evaluations or Automation executions. It is a valid remediation toolkit, but it is not the native trigger for Security Hub findings.

  • ✗

    Amazon Inspector and AWS Step Functions

    Why it's wrong here

    Amazon Inspector performs automated vulnerability assessments on EC2 instances, ECR container images, and Lambda functions, while AWS Step Functions adds orchestration to automate multi-step workflows. Inspector's findings can be integrated with Security Hub, but Inspector itself is not a consumer of Security Hub findings and cannot react to the full breadth of findings from services like IAM Access Analyzer or S3. Pairing Inspector with Step Functions would only address workload vulnerability findings, not the compliance and defensive findings that the security hub aggregation contains. Therefore, it is not the correct choice to automate responses to Security Hub findings generally.

  • ✗

    Amazon GuardDuty and AWS Lambda

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that identifies suspicious behavior (e.g., unauthorized API calls or malicious files), and Lambda can be used to isolate affected resources. GuardDuty findings are ingested by Security Hub, but the finding events originate from GuardDuty's own EventBridge event bus, not from Security Hub's consolidated findings. If you configured a Lambda trigger directly on GuardDuty, you would miss findings from other Security Hub integrated sources and also bypass the multi-account administrator aggregation that Security Hub provides. Thus, the correct integration for this scenario must consume Security Hub events, making GuardDuty + Lambda unsuited as the primary answer.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.