SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer needs to detect and respond to malware on an EC2 instance. Which TWO AWS services can be used together to achieve this? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often confuse Amazon Inspector's vulnerability scanning with malware detection, or assume CloudWatch alone can perform automated incident response, when in fact GuardDuty's Malware Protection is the only AWS-native service that directly detects malware on EC2, and Lambda is required for automated remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Lambda
AWS Lambda is correct because it can be used as a serverless compute target to automate incident response actions when malware is detected. For example, a Lambda function can be triggered by a GuardDuty finding to isolate the compromised EC2 instance by modifying security group rules or detaching the instance from an Auto Scaling group, enabling rapid, automated remediation without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs agent-based and agentless assessments of EC2 instances for software vulnerabilities, network exposure, and CIS benchmark compliance. It produces findings based on known CVEs and configuration weaknesses, but it does not scan for malicious files or execute malware-detection engines. Therefore, while Inspector can help harden an instance against future compromise, it cannot detect an active malware infection or trigger a response to it, making it incorrect for this requirement.
- ✓
AWS Lambda
Why this is correct
AWS Lambda is correct for the response side of the detect-and-respond workflow. You can configure Lambda as the target of an Amazon GuardDuty finding through EventBridge rules, then execute a custom response playbook—such as isolating the EC2 instance by detaching security groups, stopping the instance, or capturing a forensic snapshot. This serverless execution gives security teams a fast, reproducible, and policy-driven way to contain malware without provisioning a dedicated incident-response server.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring and observability service that gathers metrics, logs, and events, but it does not perform malware detection or file-level scanning on EC2 instances. It can only act on already-generated signals, such as filtering log entries and raising alarms, and it lacks threat intelligence or behavioral analytics to identify malicious code. CloudWatch might be used to trigger a Lambda function after GuardDuty reports a finding, but it is not itself the detection mechanism, so it does not satisfy the stated need.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a web application firewall that inspects HTTP(S) traffic at the application layer to block common web exploits like SQL injection and cross-site scripting. It has no visibility into the operating system, processes, memory, or disk contents of EC2 instances, so it cannot detect malware resident on the instance. While WAF could potentially block delivery of malicious web payloads, it is not a host-based malware detection or response tool, and therefore it is the wrong service for this scenario.
- ✓
Amazon GuardDuty with Malware Protection
Why this is correct
Amazon GuardDuty with Malware Protection provides the detection capability needed here. It analyzes VPC flow logs, DNS query logs, and network traffic with threat intelligence and machine learning to identify suspicious behavior, and when such behavior is correlated with an EC2 instance, it automatically triggers an agentless malware scan using an isolated snapshot of the attached EBS volume. The scan uses a combination of signature-based detection and anomaly detection to identify malware, then emits a detailed finding with severity and evidence that can be used to initiate a response, making this service correct for the detection half of the task.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.