SCS-C02 Threat Detection and Incident Response Practice Question
A company wants to automatically trigger a Lambda function when a new security finding is generated in AWS Security Hub. Which service should be used to invoke the Lambda function?
⚠ Common exam trap
Many exam-takers think Security Hub can directly invoke Lambda or that SNS is the primary integration, but AWS explicitly designed EventBridge as the central event bus for all Security Hub findings to enable flexible, rule-based routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon EventBridge
Amazon EventBridge is the correct service because AWS Security Hub automatically sends all findings to the default EventBridge bus as events. You can create an EventBridge rule that matches the 'Security Hub Findings - Imported' event pattern and targets a Lambda function for invocation. This is the native, recommended integration for event-driven responses to Security Hub findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Simple Notification Service (SNS)
Why it's wrong here
Amazon SNS is a pub/sub notification service, not the native event source for Security Hub. Security Hub publishes findings to EventBridge; an EventBridge rule can target an SNS topic, and a Lambda subscription can then be invoked, but that chain requires EventBridge as the actual trigger. Using SNS alone, there is no direct mechanism for Security Hub finding changes to invoke Lambda.
- ✗
AWS Security Hub itself
Why it's wrong here
AWS Security Hub aggregates and normalizes findings, but it has no built-in Lambda trigger capability. When findings are generated or updated, Security Hub emits events to Amazon EventBridge; it does not directly execute functions or contain trigger destinations. To invoke Lambda, you must define an EventBridge rule with an event pattern matching the Security Hub event type, making Security Hub itself insufficient as the trigger mechanism.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge is the correct answer because Security Hub natively publishes all findings and finding updates to the default event bus as events such as 'Security Hub Findings - Imported'. A rule can use an event pattern to filter on compliance status, severity, or finding type and target a Lambda function, which EventBridge then invokes asynchronously. This is the standard event-driven integration designed for automating responses to Security Hub findings.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API activity in Security Hub, such as BatchImportFindings or EnableSecurityHub, but it does not forward finding data itself. Lambda can be triggered from CloudTrail only by creating a CloudWatch Logs subscription on the CloudTrail log group and parsing logs, which is indirect and primarily for auditing, not for real-time findings. The native event stream for Security Hub findings is EventBridge, not CloudTrail.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.