SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to centralize threat detection and automatically remediate high-severity GuardDuty findings across all accounts. What is the MOST efficient way to achieve this?
⚠ Common exam trap
Many candidates assume Security Hub (Option D) is required for centralization, but GuardDuty's delegated administrator feature already provides native centralized finding management without additional services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts
AWS Organizations allows you to enable GuardDuty in the management account and designate a delegated administrator, which automatically enables GuardDuty across all member accounts and centralizes finding management. This approach eliminates the need for per-account configuration or cross-account IAM roles, as the delegated administrator can view and manage findings from all accounts in a single GuardDuty console. It is the most efficient method because it leverages native AWS Organizations integration for automated, centralized threat detection and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts
Why this is correct
Designating a GuardDuty delegated administrator in AWS Organizations is the native, recommended pattern because it uses the service's integration with Organizations to auto-enable GuardDuty for every current and future member account via a single API call. The delegated administrator account receives a centralized view of all findings and can configure threat detection policies, while individual accounts retain read access to their own results. This eliminates per-account manual steps and provides a consistent audit trail of enablement state across the organization.
- ✗
Create a Lambda function that enables GuardDuty in each account using cross-account IAM roles
Why it's wrong here
Writing a custom Lambda function that assumes cross-account IAM roles to enable GuardDuty replicates, in a brittle way, what the Organizations integration already does natively. It requires you to manage the lifecycle of new accounts, handle retry and error scenarios for each region, and store or assume credentials securely, but it still leaves you with no single console or consolidated findings pane—you'd need a separate mechanism (such as Security Hub or EventBridge) to aggregate the results. This approach also breaks down in accounts where the role trust policy or required permissions are not perfectly aligned, making it operationally fragile and unnecessarily complex.
- ✗
Configure Amazon EventBridge to forward findings from each account to a central account
Why it's wrong here
Configuring EventBridge rules to forward GuardDuty findings from each account to a central account is a post-detection pattern; it only routes events that GuardDuty has already generated, so it does nothing to provision or activate the service in member accounts. Even if every account were enabled, EventBridge delivers individual finding events, but it does not supply the aggregated dashboard, suppression rules, or threat list management that the delegated administrator model offers. For an organization that has not yet enabled GuardDuty anywhere, this approach would result in zero findings because the service itself never gets turned on.
- ✗
Use AWS Security Hub and enable GuardDuty in each account separately
Why it's wrong here
Using Security Hub to aggregate findings across accounts presupposes GuardDuty is enabled and each account is sending data—Security Hub simply ingests GuardDuty findings through cross-product integrations, it cannot enable GuardDuty on your behalf or configure data sources like DNS or VPC flow logs. Actually, Security Hub itself requires you to enable it in each account and region, then you have to additionally configure GuardDuty separately in every account, doubling the manual effort. The result is a dashboard, but no centralized enforcement of GuardDuty enablement; new accounts will silently not be monitored unless you add yet another automation script.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.