SCS-C02 Threat Detection and Incident Response Practice Question
A security team is designing an automated incident response system. The system must meet the following requirements: (1) automatically respond to GuardDuty findings, (2) ensure that response actions are logged and immutable, and (3) allow for human approval before destructive actions. Which services should the team use? (Select THREE.)
⚠ Common exam trap
The trap here is that candidates often select Lambda as the sole compute service, overlooking that Step Functions is required to orchestrate the human approval step and that CloudTrail is needed for immutable logging, not just EventBridge and Lambda alone.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon EventBridge
Amazon EventBridge (A) is correct because it can receive GuardDuty findings in near real-time and route them to downstream targets for automated response. This enables the first requirement by triggering workflows directly from GuardDuty events without custom polling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon EventBridge
Why this is correct
Amazon EventBridge is the correct entry point because GuardDuty publishes every finding to the default event bus as an event with a detail-type such as 'GuardDuty Finding'. A rule can filter on finding severity, account, or region and immediately invoke a Step Functions state machine or Lambda function, enabling real-time, event-driven response. Without EventBridge, you would have to poll the GuardDuty API, which introduces latency and bypasses the native event pattern that AWS services emit.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is correct in the incident-response architecture because it records every management and data-plane API call as a JSON audit log, giving you a forensic record of actions before, during, and after an incident. It does not initiate response actions; instead, it supports root-cause analysis and compliance by preserving evidence, especially when delivered to an S3 bucket with Object Lock or encrypted with KMS and validated with log file integrity. This audit trail allows responders to determine what changed and by which principal, which is essential for containment and recovery decisions.
- ✓
AWS Step Functions
Why this is correct
AWS Step Functions is correct because it lets you define a durable state machine that coordinates multiple incident-response tasks, such as isolating an EC2 instance, invoking Lambda for enrichment, and pausing for an approval via the 'Wait for Callback with Task Token' pattern. It maintains execution state, retries failed steps, and supports human-approval timeouts, which EventBridge rules or notification services cannot do. Step Functions should be the target of the EventBridge rule that receives the GuardDuty finding, so the full response workflow is repeatable and auditable.
- ✗
AWS Lambda
Why it's wrong here
AWS Lambda is wrong as the core automation component because it is a single-purpose compute service; it executes a function and then ends, with no native mechanism to track multi-step workflow state, retry an entire sequence, or pause for human approval. You could hand-code orchestration in Python or Node.js, but that requires custom state storage, timeout handling, and approval logic, making it brittle and hard to operate. Lambda is best used as a building block inside a Step Functions state machine, not as the orchestrator itself.
- ✗
Amazon Simple Notification Service (SNS)
Why it's wrong here
Amazon Simple Notification Service (SNS) is wrong because it is a pub/sub messaging service that simply fans out a message to subscribers such as Lambda, SQS, email, or HTTP endpoints. It cannot maintain workflow state, coordinate sequential tasks, or wait for a human decision, so it is not a substitute for Step Functions. In this design, SNS would be useful only as a supporting notification channel—for example, alerting responders when an EventBridge rule fires or when a Step Functions approval task completes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.