SCS-C02 Threat Detection and Incident Response Practice Question
A company wants to implement automated remediation of security findings from Amazon GuardDuty. Which THREE AWS services can be used together to create an automated response workflow? (Select THREE.)
⚠ Common exam trap
The trap here is that candidates often select Amazon SQS or AWS Config because they are associated with event-driven architectures or compliance, but they are not the core services used in the standard GuardDuty automated remediation pattern, which relies on EventBridge, Lambda, and Step Functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Events (EventBridge)
Amazon GuardDuty sends findings to Amazon CloudWatch Events (EventBridge) as events. You can configure an EventBridge rule to match specific GuardDuty findings and trigger an AWS Lambda function for automated remediation. AWS Step Functions can orchestrate complex remediation workflows involving multiple Lambda functions or other AWS services, providing retry logic and error handling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Events (EventBridge)
Why this is correct
Amazon CloudWatch Events (EventBridge) is the correct primary service because GuardDuty natively publishes findings to the EventBridge default event bus as structured events. An EventBridge rule can filter on finding fields (e.g., severity, type, account ID) and route matched findings to targets such as Lambda functions or Step Functions state machines, enabling near-real-time automated remediation without custom polling. This is the standard, serverless integration point for GuardDuty-driven responses.
- ✓
AWS Lambda
Why this is correct
AWS Lambda is the compute service that executes the actual remediation actions, such as modifying a security group rule to restrict access, detaching an instance from the network, or invoking an AWS Systems Manager document. Each Lambda function receives the GuardDuty finding as an event payload, parses relevant metadata (IP, instance ID, port), and makes the necessary AWS API calls. It is serverless and scales automatically, and can be triggered directly by EventBridge or called as a step within a Step Functions workflow.
- ✓
AWS Step Functions
Why this is correct
AWS Step Functions is a workflow orchestration service that coordinates multi-step remediation processes, such as isolate, snapshot, investigate, and terminate. It is appropriate when remediation requires branching logic, retries with timeouts, human approval, or integration across multiple Lambda functions and AWS services. Instead of coding a state machine in a single Lambda, Step Functions provides durable state management and visibility, making it a complementary tool to Lambda but not the service that ingests GuardDuty findings.
- ✗
Amazon SQS
Why it's wrong here
Amazon SQS is a managed message queue service, but it is not a primary service in the GuardDuty automated remediation architecture. EventBridge already delivers GuardDuty findings directly to targets like Lambda or Step Functions, so inserting an SQS queue adds unnecessary latency and operational overhead. SQS could be useful for decoupling or buffering if the remediation workload requires a queue, but it is not the service that receives and filters GuardDuty findings, and using it as the core could be considered overengineering.
- ✗
AWS Config
Why it's wrong here
AWS Config is a configuration compliance and auditing service that records resource configuration changes and evaluates them against rules; it is not designed to consume or act on GuardDuty security findings. While AWS Config supports automatic remediation of noncompliant resources through SSM automation, that applies to configuration drift, not to security findings like suspicious API calls or malicious IP connections. GuardDuty findings are sent to EventBridge, not to AWS Config, so Config cannot be the direct trigger for this remediation workflow.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.