SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer needs to ensure that all findings from member accounts are visible in the administrator account. Additionally, the engineer wants to receive real-time notifications for high-severity findings. Which TWO actions should the engineer take? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to think Amazon Detective or AWS Config are needed for real-time notifications, but Detective is for post-incident analysis and Config is for compliance drift, not for triggering alerts on security findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Designate an administrator account in GuardDuty to manage the multi-account environment.
Designating an administrator account in GuardDuty is the required step to centrally manage findings from all member accounts in an AWS Organizations multi-account setup. This configuration enables the administrator account to view and aggregate all findings from member accounts without needing to log into each account individually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Amazon Detective to analyze GuardDuty findings.
Why it's wrong here
Amazon Detective is a post-event investigation service that visualizes and analyzes cloud resources to help you identify the root cause of a GuardDuty finding. It does not emit alerts or notify you when a high-severity finding is detected, and it does not play a role in the initial configuration of a multi-account GuardDuty deployment. Detective is invoked after a finding occurs to expedite forensic analysis, but it is not a substitute for a real-time notification channel.
- ✓
Designate an administrator account in GuardDuty to manage the multi-account environment.
Why this is correct
GuardDuty multi-account architecture requires you to designate an administrator account (via AWS Organizations delegated administrator or invitation) that owns the GuardDuty detectors and manages all member accounts. The administrator account aggregates findings from every member account, giving you a single-pane-of-glass view and allowing you to configure threat lists and managed rules centrally. This designated administrator is the foundation for cross-account management and is mandatory for any multi-account GuardDuty setup.
- ✓
Create an Amazon EventBridge rule that triggers an SNS notification for high-severity GuardDuty findings.
Why this is correct
GuardDuty emits every finding as an event on the default EventBridge bus, allowing you to create a rule with a severity filter (e.g., severity >= 7) to trigger an SNS topic. This rule delivers real-time alerts via email, SMS, or HTTP when high-severity findings occur, and can also invoke Lambda for automated response. This is the correct mechanism for immediate notification, as GuardDuty has no native alerting feature and relies on EventBridge integrations.
- ✗
Enable AWS CloudTrail in all member accounts to log GuardDuty API calls.
Why it's wrong here
AWS CloudTrail records API activity for GuardDuty configuration changes such as creating a detector or updating membership, but the findings themselves are not API calls and therefore do not appear in CloudTrail logs. CloudTrail is an audit trail for who did what, not a data source for threat findings. Enabling CloudTrail in all member accounts may be good security hygiene, but it does nothing to aggregate or forward GuardDuty findings to a central location.
- ✗
Use AWS Config to monitor GuardDuty configuration.
Why it's wrong here
AWS Config provides configuration history and compliance rules for AWS resources, such as verifying that GuardDuty is enabled on each account, but it does not stream or act on the security findings GuardDuty produces. Config rules evaluate resource state against desired policies and are not designed for real-time, severity-aware alerting. While Config can confirm your GuardDuty configuration exists, it cannot notify you of an active threat finding, making it irrelevant to this requirement.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.