SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is implementing automated incident response. The engineer wants to use AWS Lambda to automatically remediate GuardDuty findings. What is the recommended pattern to trigger the Lambda function?
⚠ Common exam trap
Many exam-takers assume GuardDuty uses SNS or CloudWatch Logs for output, similar to other AWS services, but GuardDuty exclusively emits findings as EventBridge events, making EventBridge the only native and recommended trigger pattern for Lambda remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an Amazon EventBridge rule to match GuardDuty findings and invoke the Lambda function.
Amazon EventBridge is the recommended pattern because it natively integrates with AWS GuardDuty to receive all finding events in near real-time. By configuring an EventBridge rule that matches GuardDuty finding types (e.g., 'UnauthorizedAccess:EC2/SSHBruteForce'), you can directly invoke a Lambda function for automated remediation without polling or intermediate services. This pattern is serverless, event-driven, and follows AWS best practices for decoupled incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an Amazon EventBridge rule to match GuardDuty findings and invoke the Lambda function.
Why this is correct
EventBridge is GuardDuty's native event bus integration. GuardDuty automatically publishes each finding as an event to the default event bus, where a rule can match the detail-type 'GuardDuty Finding' and use Lambda as a target. The rule supports filtering by severity, account, or finding type, and Lambda receives the finding JSON directly, enabling precise, low-latency automated remediation. This is the architecturally supported pattern with built-in retry and optional dead-letter queues.
- ✗
Subscribe the Lambda function to an SNS topic that GuardDuty publishes findings to.
Why it's wrong here
This pattern is not supported by GuardDuty: GuardDuty does not publish findings to an SNS topic directly. Instead, findings are emitted as EventBridge events, and if a notification is desired, an EventBridge rule must first route the finding to an SNS topic as a target. Directly subscribing a Lambda function to a GuardDuty SNS topic would require a manually-created publisher that duplicates findings, adds latency, and risks missing events unless you build a separate polling mechanism.
- ✗
Use CloudWatch Logs subscription filter to trigger Lambda on GuardDuty log entries.
Why it's wrong here
GuardDuty never writes its findings to CloudWatch Logs as log entries, so a log subscription filter has no GuardDuty data to match. A CloudWatch Logs subscription filter is intended for VPC Flow Logs, CloudTrail logs, or application log groups, not for GuardDuty finding streams. Even if you configure it, the filter pattern will never match because there is no corresponding log group or log stream containing GuardDuty finding JSON. The real-time integration point is EventBridge, not Logs.
- ✗
Have the Lambda function poll the EC2 instance metadata for threat indicators.
Why it's wrong here
EC2 instance metadata (accessed at http://169.254.169.254/latest/meta-data) contains instance identity, IAM role, or user data, but it has no relationship to GuardDuty findings. GuardDuty generates findings by analyzing VPC DNS logs, VPC Flow Logs, and threat intelligence, and it publishes those findings through its API and EventBridge. Polling metadata would neither retrieve findings nor trigger a Lambda function; it would also add unnecessary custom infrastructure, latency, and credential-handling risk compared to the event-driven EventBridge integration.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.