SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is configuring an automated response to a GuardDuty finding that indicates a compromised EC2 instance. The engineer wants to isolate the instance by changing its security group to a 'quarantine' group. Which AWS service is BEST suited to automate this response?
⚠ Common exam trap
It's easy for candidates to confuse AWS Systems Manager Automation as the primary automation service, forgetting that it requires an event source like EventBridge to trigger it, making EventBridge the correct answer for the 'best suited' service to automate the response directly from GuardDuty.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon EventBridge
Amazon EventBridge is the best choice because it can directly receive GuardDuty findings as events and trigger an automated response, such as invoking a Lambda function or Systems Manager Automation runbook to change the EC2 instance's security group to a quarantine group. EventBridge provides native integration with GuardDuty via its default event bus, enabling real-time, event-driven automation without additional orchestration overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Step Functions
Why it's wrong here
AWS Step Functions is a workflow orchestration service, not an event source. While you can build a state machine to respond to GuardDuty findings, Step Functions has no native way to detect those findings; it must be invoked by an external event such as an EventBridge rule. Without that EventBridge trigger, Step Functions cannot initiate an automated response on its own, making it the wrong answer for the trigger mechanism.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records resource configuration changes and evaluates them against rules to determine compliance, but it is not designed to process real-time security findings like GuardDuty alerts. Although Config can trigger auto-remediation actions for non-compliant resources, those actions are tied to configuration drift, not to threat detection events. GuardDuty findings arrive through EventBridge, not through Config, so Config cannot serve as the automated response trigger.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge is the correct trigger because GuardDuty natively publishes all findings to the EventBridge default bus as events. A security engineer can create a rule with an event pattern matching GuardDuty finding types, then set a Lambda function as the target to automatically remediate or alert. EventBridge provides real-time, serverless event delivery without custom polling, making it the designed integration point for GuardDuty findings.
- ✗
AWS Systems Manager Automation
Why it's wrong here
AWS Systems Manager Automation is a runbook-driven service for operational remediation, such as patching instances or restarting services, and it requires an explicit invocation—it does not monitor for security findings. It can be used as a target of an EventBridge rule to perform remediation, but it is not the native event source for GuardDuty alerts. By default, Systems Manager Automation has no event-driven behavior and depends on SSM agent availability, so it is not the correct answer for triggering the response.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.