Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is designing a threat detection solution for a multi-account AWS environment. The engineer needs to detect and respond to suspicious API activity across all accounts. Which TWO services should be used together to achieve this? (Choose two.)

⚠ Common exam trap

Candidates often confuse AWS Security Hub (a findings aggregation and compliance service) with a primary detection tool, but Security Hub itself does not generate threat detections—it ingests findings from GuardDuty and other services, so both are needed together.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior across AWS accounts, including suspicious API activity. By enabling GuardDuty in all accounts and aggregating findings to a central administrator account, it provides the necessary detection layer for multi-account environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is AWS's monitoring and observability platform for collecting metrics, logs, and events and setting alarms. While it can ingest VPC Flow Logs or CloudTrail logs and trigger alerts on static thresholds, it has no built-in threat detection, anomaly-detection model, or security-finding engine. Thus it can support a detection workflow by surfacing data, but it is not the threat detection service itself.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a machine-learning and anomaly-detection security service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs to identify unauthorized behavior, crypto-mining, credential compromise, and API abuse. It generates severity-ranked findings using threat intelligence and behavioral modeling, making it the core service for a threat detection solution.

  • ✓

    AWS Security Hub

    Why this is correct

    AWS Security Hub acts as a centralized security findings aggregator that ingests GuardDuty findings, along with findings from Inspector, IAM Access Analyzer, and Firewall Manager, and applies CIS AWS Foundations and other controls. While it is not the service that performs raw threat detection, it is correct for consolidating GuardDuty detections across accounts and Regions into one actionable dashboard and enabling automated response through EventBridge.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans compute workloads for software vulnerabilities, unintended network exposure, and deviations from security best practices. It does not analyze suspicious API activity, DNS anomalies, or VPC traffic patterns as GuardDuty does, so it is the wrong choice for a threat-detection solution focused on signs of active compromise.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records and evaluates AWS resource configuration changes against desired policies and compliance rules. Its focus is configuration drift and resource inventory, not behavioral threat detection, so while it can detect a security group change after a compromise, it cannot identify the malicious, anomalous actions that GuardDuty is designed to find.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.