Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is configuring automated incident response for Amazon GuardDuty findings. The engineer wants to isolate a compromised EC2 instance by changing its security group and stopping the instance. Which THREE services should the engineer use together to achieve this? (Choose THREE.)

⚠ Common exam trap

A common mix-up: candidates think AWS Config can directly remediate findings (e.g., via AWS Config Rules with auto-remediation), but Config only triggers evaluations and cannot perform actions like stopping instances or modifying security groups without a separate automation service like SSM or Lambda.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Systems Manager

AWS Systems Manager (SSM) is correct because it provides the Automation runbook capability that can be used to stop an EC2 instance and modify its security groups as part of an incident response workflow. SSM Automation can be triggered by an EventBridge rule and can invoke Lambda functions or run commands directly on the instance to isolate it. This allows the security engineer to automate the isolation and stopping of the compromised instance without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon EC2

    Why it's wrong here

    Amazon EC2 is a compute service that provides virtual servers, and in this architecture the EC2 instance itself is the resource that would be isolated or stopped — not the service that orchestrates the response. EC2 does not natively consume GuardDuty findings, execute automation runbooks, or perform cross-service remediation actions. It is the target of the remediation, so it cannot serve as the incident response orchestrator.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is designed for continuous compliance monitoring by recording and evaluating changes to resource configurations against managed or custom rules. While Config can trigger Lambda for auto-remediation, it does not natively ingest GuardDuty security findings as real-time events, and its evaluation cycle is configuration-change-driven rather than finding-driven. Therefore it is not the correct service to directly orchestrate a real-time response to a GuardDuty finding.

  • ✓

    AWS Systems Manager

    Why this is correct

    AWS Systems Manager is the correct choice because its Automation service provides pre-built and custom runbooks that can execute the remediation workflow, such as isolating an EC2 instance using the aws:stopInstance or aws:executeAwsApi actions. These runbooks can be triggered by an EventBridge rule that filters GuardDuty findings, and they support step-by-step error handling, conditional logic, and IAM-based approvals for safe, auditable incident response. This makes SSM the orchestrator that actually performs the automated isolation.

  • ✓

    Amazon EventBridge

    Why this is correct

    Amazon EventBridge is a correct component in the solution because it acts as the real-time event router that receives GuardDuty findings from the default event bus and filters them using event patterns based on finding type or severity. It then delivers those events to targets such as AWS Lambda functions or Systems Manager Automation documents, making it the essential trigger mechanism that sets the response in motion. However, it only routes the event; it does not itself execute the remediation steps.

  • ✓

    AWS Lambda

    Why this is correct

    AWS Lambda is correct as a serverless compute service that can run custom remediation logic in response to a GuardDuty finding delivered by EventBridge. A Lambda function can use the AWS SDK to stop, isolate, or terminate EC2 instances, modify security groups, or detach an instance from an Auto Scaling group, providing maximum flexibility for bespoke response actions. It is well suited for injecting custom steps like tagging the instance or notifying a security team, though it requires writing and maintaining code rather than using a managed runbook.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.