Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to centralize threat detection and automatically remediate high-severity GuardDuty findings across all accounts. What is the MOST efficient way to achieve this?

⚠ Common exam trap

Many candidates assume Security Hub (Option D) is required for centralization, but GuardDuty's delegated administrator feature already provides native centralized finding management without additional services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts

AWS Organizations allows you to enable GuardDuty in the management account and designate a delegated administrator, which automatically enables GuardDuty across all member accounts and centralizes finding management. This approach eliminates the need for per-account configuration or cross-account IAM roles, as the delegated administrator can view and manage findings from all accounts in a single GuardDuty console. It is the most efficient method because it leverages native AWS Organizations integration for automated, centralized threat detection and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts

    Why this is correct

    Designating a GuardDuty delegated administrator in AWS Organizations is the native, recommended pattern because it uses the service's integration with Organizations to auto-enable GuardDuty for every current and future member account via a single API call. The delegated administrator account receives a centralized view of all findings and can configure threat detection policies, while individual accounts retain read access to their own results. This eliminates per-account manual steps and provides a consistent audit trail of enablement state across the organization.

  • ✗

    Create a Lambda function that enables GuardDuty in each account using cross-account IAM roles

    Why it's wrong here

    Writing a custom Lambda function that assumes cross-account IAM roles to enable GuardDuty replicates, in a brittle way, what the Organizations integration already does natively. It requires you to manage the lifecycle of new accounts, handle retry and error scenarios for each region, and store or assume credentials securely, but it still leaves you with no single console or consolidated findings pane—you'd need a separate mechanism (such as Security Hub or EventBridge) to aggregate the results. This approach also breaks down in accounts where the role trust policy or required permissions are not perfectly aligned, making it operationally fragile and unnecessarily complex.

  • ✗

    Configure Amazon EventBridge to forward findings from each account to a central account

    Why it's wrong here

    Configuring EventBridge rules to forward GuardDuty findings from each account to a central account is a post-detection pattern; it only routes events that GuardDuty has already generated, so it does nothing to provision or activate the service in member accounts. Even if every account were enabled, EventBridge delivers individual finding events, but it does not supply the aggregated dashboard, suppression rules, or threat list management that the delegated administrator model offers. For an organization that has not yet enabled GuardDuty anywhere, this approach would result in zero findings because the service itself never gets turned on.

  • ✗

    Use AWS Security Hub and enable GuardDuty in each account separately

    Why it's wrong here

    Using Security Hub to aggregate findings across accounts presupposes GuardDuty is enabled and each account is sending data—Security Hub simply ingests GuardDuty findings through cross-product integrations, it cannot enable GuardDuty on your behalf or configure data sources like DNS or VPC flow logs. Actually, Security Hub itself requires you to enable it in each account and region, then you have to additionally configure GuardDuty separately in every account, doubling the manual effort. The result is a dashboard, but no centralized enforcement of GuardDuty enablement; new accounts will silently not be monitored unless you add yet another automation script.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.