SCS-C02 Threat Detection and Incident Response Practice Question
A company uses AWS Systems Manager Patch Manager to apply patches to EC2 instances. The security team wants to ensure that instances are patched within 7 days of a patch release. Which service should be used to monitor and report compliance?
⚠ Common exam trap
A common mix-up: candidates confuse Amazon Inspector's vulnerability scanning with patch compliance monitoring, but Inspector does not track whether patches have been applied within a specific time window after release—it only identifies missing patches or vulnerabilities at a point in time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations, including patch compliance status via Systems Manager Patch Manager. You can create an AWS Config rule (e.g., 'ec2-managedinstance-patch-compliance-status') that checks whether instances have the required patches installed within a specified time frame (e.g., 7 days). AWS Config then reports noncompliant resources, enabling the security team to track and remediate patching gaps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config integrates with Systems Manager Patch Manager to record patch compliance state as a configuration item. You can use managed rules like ec2-managedinstance-patch-compliance-status-check or custom Lambda rules to evaluate whether instances are patched within the required timeframe, and trigger remediation actions such as Systems Manager Automation. It provides an ongoing compliance history and can enforce patch validation across the fleet.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub aggregates security findings from various AWS services, including Config and Inspector, into a centralized dashboard. It does not perform its own patch scanning or assess patch compliance timelines. Any patch-related data in Security Hub originates from other services, so it cannot be used directly to enforce or validate patch deadlines, making it a secondary aggregator rather than the primary compliance mechanism.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that identifies software vulnerabilities and unintended network exposure using CVE data and network reachability analysis. It reports issues like known exploits or excessive exposure, but it does not track whether an instance's patches align with a specific compliance schedule or remediation timeframe. Inspector's model is based on risk level, not on 'patched within X days' compliance checks, so it cannot fulfill the requirement of verifying patch application within a defined period.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is an advisory service that inspects your account for best practices across cost optimization, performance, security, and fault tolerance, such as unused security groups or IAM key rotation. It has no checks that evaluate the patch status of EC2 instances or the compliance of Systems Manager Patch Manager operations. Since it does not track patch timelines or instance-level compliance, it is not applicable to monitoring patch application within a specific timeframe.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.