SCS-C02 Threat Detection and Incident Response Practice Question
A company wants to detect and respond to potential security threats in near real-time. Which TWO services should the company use together to achieve this? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse AWS Config or CloudTrail as threat detection services, but they are primarily configuration auditing and API logging tools, respectively, and lack the real-time threat analysis capabilities of GuardDuty and Security Hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub (D) aggregates security findings from multiple AWS services, including Amazon GuardDuty, and provides a comprehensive view of security alerts and compliance status. Amazon GuardDuty (E) is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning and integrated threat intelligence. Together, they enable near real-time detection and response by centralizing findings from GuardDuty in Security Hub, which can trigger automated remediation workflows via Amazon EventBridge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration auditing and compliance service that records resource configuration changes and evaluates them against managed or custom rules. It does not inspect network traffic, analyze API call patterns, or identify active threats such as compromised credentials or malicious behavior, so it cannot provide real-time threat detection. While Config can detect risky configuration drift that may lead to exposure, it is not a dedicated security threat detection and response service.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs agent-based and agentless scans of workloads for software vulnerabilities (CVEs) and unintended network exposure. Its assessments run on a schedule or event-based trigger and produce a static list of findings, rather than continuously monitoring live activity for signs of an ongoing attack. This makes it valuable for hardening, but not suitable as the primary real-time threat detection and automated response mechanism.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records the complete history of API activity across your account, including the identity, time, and source IP for each request, for audit and governance purposes. However, CloudTrail is a log-generation service; it does not itself evaluate those events for malicious patterns, generate security findings, or take automated remediation actions. Detecting threats from CloudTrail logs requires additional analytics or detective services, so it is not a standalone detection and response solution.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub is the correct choice because it aggregates and correlates security findings from multiple sources, including GuardDuty, Inspector, and Config, into a single, prioritized view. It applies continuous security best-practice and compliance checks, and its integration with Amazon EventBridge allows you to automate responses by triggering AWS Lambda, Systems Manager, or Step Functions workflows. This centralized detect-and-respond architecture is exactly what the company needs for operational security monitoring.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a correct detection service because it uses machine learning, anomaly detection, and threat intelligence to continuously analyze VPC flow logs, DNS logs, and CloudTrail management events for suspicious activity such as crypto mining, credential compromise, or unusual API calls. It generates findings in near real time that can be sent to Security Hub and used to trigger automated remediation via EventBridge. While GuardDuty excels at discovering threats, it is not itself a response orchestration platform, but it is an essential part of the detect-and-respond solution.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.