Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Organizations with multiple accounts. The security team needs a centralized solution to automatically initiate incident response runbooks across all accounts when a threat is detected. Which approach meets these requirements?

⚠ Common exam trap

Candidates often assume GuardDuty's built-in remediation actions are sufficient for centralized multi-account response, but those actions are per-account and lack the orchestration and customization of Security Hub + EventBridge + Systems Manager Automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Security Hub with cross-account aggregation and Amazon EventBridge to trigger AWS Systems Manager Automation runbooks.

AWS Security Hub with cross-account aggregation collects findings from all accounts into a single administrator account. Amazon EventBridge can then be configured to match specific Security Hub findings (e.g., a GuardDuty threat detection) and trigger AWS Systems Manager Automation runbooks. This provides a centralized, automated incident response mechanism across all accounts without requiring per-account Lambda functions or manual remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS Security Hub with cross-account aggregation and Amazon EventBridge to trigger AWS Systems Manager Automation runbooks.

    Why this is correct

    Security Hub's cross-account aggregation consolidates findings from all member accounts into a single delegated administrator account, enabling a central view of threats. You can then create EventBridge rules that match specific finding types and trigger Systems Manager Automation runbooks, which can execute remediation actions directly in the affected member account. This provides centralized, event-driven response without manually managing each account individually.

  • ✗

    Enable Amazon GuardDuty in all accounts and use its built-in remediation actions.

    Why it's wrong here

    Amazon GuardDuty's built-in remediation actions are largely per-account and operate only within a single account's environment; they do not aggregate findings or orchestrate actions across multiple accounts. While GuardDuty can generate findings and some rules can trigger Lambda or S3 actions, it lacks a central management plane for coordinated incident response across all accounts in an organization. Therefore, relying solely on GuardDuty's built-in actions would require configuring and managing each account separately, which is not a centralized solution.

  • ✗

    Configure AWS CloudFormation StackSets to deploy incident response stacks in all accounts.

    Why it's wrong here

    CloudFormation StackSets are designed to deploy infrastructure as code across multiple accounts and regions, such as creating security templates, IAM roles, or baseline resources. However, they are not event-driven and do not react to live findings; deploying an 'incident response stack' does not automatically execute a response when a security finding occurs. You would still need an event mechanism, such as EventBridge, to invoke actions, making StackSets an infrastructure provisioning tool rather than an actual response orchestration solution.

  • ✗

    Deploy an AWS Lambda function in each member account to respond to findings.

    Why it's wrong here

    Deploying an individual Lambda function in each member account to respond to findings would require per-account deployment, configuration, and permission management, creating significant operational overhead. It also fragments visibility, since there is no central aggregator or coordinated trigger to ensure consistent and timely responses across the organization. This approach lacks the centralized aggregation and orchestration that Security Hub plus EventBridge provides, making it less effective and harder to govern.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.