Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is configuring an automated response to a GuardDuty finding that indicates a compromised EC2 instance. The engineer wants to isolate the instance by changing its security group to a 'quarantine' group. Which AWS service is BEST suited to automate this response?

⚠ Common exam trap

It's easy for candidates to confuse AWS Systems Manager Automation as the primary automation service, forgetting that it requires an event source like EventBridge to trigger it, making EventBridge the correct answer for the 'best suited' service to automate the response directly from GuardDuty.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon EventBridge

Amazon EventBridge is the best choice because it can directly receive GuardDuty findings as events and trigger an automated response, such as invoking a Lambda function or Systems Manager Automation runbook to change the EC2 instance's security group to a quarantine group. EventBridge provides native integration with GuardDuty via its default event bus, enabling real-time, event-driven automation without additional orchestration overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Step Functions

    Why it's wrong here

    AWS Step Functions is a workflow orchestration service, not an event source. While you can build a state machine to respond to GuardDuty findings, Step Functions has no native way to detect those findings; it must be invoked by an external event such as an EventBridge rule. Without that EventBridge trigger, Step Functions cannot initiate an automated response on its own, making it the wrong answer for the trigger mechanism.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records resource configuration changes and evaluates them against rules to determine compliance, but it is not designed to process real-time security findings like GuardDuty alerts. Although Config can trigger auto-remediation actions for non-compliant resources, those actions are tied to configuration drift, not to threat detection events. GuardDuty findings arrive through EventBridge, not through Config, so Config cannot serve as the automated response trigger.

  • ✓

    Amazon EventBridge

    Why this is correct

    Amazon EventBridge is the correct trigger because GuardDuty natively publishes all findings to the EventBridge default bus as events. A security engineer can create a rule with an event pattern matching GuardDuty finding types, then set a Lambda function as the target to automatically remediate or alert. EventBridge provides real-time, serverless event delivery without custom polling, making it the designed integration point for GuardDuty findings.

  • ✗

    AWS Systems Manager Automation

    Why it's wrong here

    AWS Systems Manager Automation is a runbook-driven service for operational remediation, such as patching instances or restarting services, and it requires an explicit invocation—it does not monitor for security findings. It can be used as a target of an EventBridge rule to perform remediation, but it is not the native event source for GuardDuty alerts. By default, Systems Manager Automation has no event-driven behavior and depends on SSM agent availability, so it is not the correct answer for triggering the response.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.