Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A company uses AWS Systems Manager Patch Manager to apply patches to EC2 instances. The security team wants to ensure that instances are patched within 7 days of a patch release. Which service should be used to monitor and report compliance?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Inspector's vulnerability scanning with patch compliance monitoring, but Inspector does not track whether patches have been applied within a specific time window after release—it only identifies missing patches or vulnerabilities at a point in time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations, including patch compliance status via Systems Manager Patch Manager. You can create an AWS Config rule (e.g., 'ec2-managedinstance-patch-compliance-status') that checks whether instances have the required patches installed within a specified time frame (e.g., 7 days). AWS Config then reports noncompliant resources, enabling the security team to track and remediate patching gaps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config integrates with Systems Manager Patch Manager to record patch compliance state as a configuration item. You can use managed rules like ec2-managedinstance-patch-compliance-status-check or custom Lambda rules to evaluate whether instances are patched within the required timeframe, and trigger remediation actions such as Systems Manager Automation. It provides an ongoing compliance history and can enforce patch validation across the fleet.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub aggregates security findings from various AWS services, including Config and Inspector, into a centralized dashboard. It does not perform its own patch scanning or assess patch compliance timelines. Any patch-related data in Security Hub originates from other services, so it cannot be used directly to enforce or validate patch deadlines, making it a secondary aggregator rather than the primary compliance mechanism.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that identifies software vulnerabilities and unintended network exposure using CVE data and network reachability analysis. It reports issues like known exploits or excessive exposure, but it does not track whether an instance's patches align with a specific compliance schedule or remediation timeframe. Inspector's model is based on risk level, not on 'patched within X days' compliance checks, so it cannot fulfill the requirement of verifying patch application within a defined period.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is an advisory service that inspects your account for best practices across cost optimization, performance, security, and fault tolerance, such as unused security groups or IAM key rotation. It has no checks that evaluate the patch status of EC2 instances or the compliance of Systems Manager Patch Manager operations. Since it does not track patch timelines or instance-level compliance, it is not applicable to monitoring patch application within a specific timeframe.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.