Courseiva

SCS-C02 Management and Security Governance Practice Question

A security team wants to centrally manage and automatically remediate findings across 40 AWS accounts in an organization. They need a solution that aggregates security findings from GuardDuty, Inspector, and Macie into one place and can trigger automated remediation runbooks. Which combination of services BEST meets these requirements?

⚠ Common exam trap

The trap here is assuming AWS Config automatic remediation can act on GuardDuty, Inspector, or Macie findings, when Config remediation is scoped to Config rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.

Security Hub with organization integration ingests and normalizes findings from GuardDuty, Inspector, and Macie across all accounts, providing a single aggregation point. EventBridge rules can match Security Hub findings and invoke Systems Manager Automation runbooks for automated remediation. Trusted Advisor, Detective, and CloudTrail Lake do not aggregate these detection findings, and scheduled or S3-triggered remediation lacks native integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Amazon Detective in all accounts and forward findings to a central S3 bucket, then use AWS Lambda functions triggered by S3 event notifications for remediation.

    Why it's wrong here

    Amazon Detective helps investigate and analyze security findings but is not an aggregation service for GuardDuty, Inspector, and Macie. Forwarding findings to S3 and triggering Lambda on object creation adds latency and complexity, and does not provide the native normalization and cross-account aggregation that Security Hub offers for these sources.

  • ✗

    Enable AWS CloudTrail Lake in all accounts and create queries that detect GuardDuty, Inspector, and Macie findings, then use EventBridge Scheduler to run remediation scripts.

    Why it's wrong here

    CloudTrail Lake stores and queries CloudTrail events, not the findings generated by GuardDuty, Inspector, or Macie. Those services publish findings through their own APIs and Security Hub, not as CloudTrail management events. EventBridge Scheduler runs tasks on a schedule rather than reacting to findings, so remediation would not be event-driven.

  • ✓

    Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.

    Why this is correct

    Security Hub aggregates findings from GuardDuty, Inspector, and Macie across organization accounts when centralized configuration is enabled. EventBridge can match Security Hub findings and invoke Systems Manager Automation runbooks to remediate automatically. This combination provides both centralized aggregation and automated response, directly satisfying the stated requirements for 40 accounts.

  • ✗

    Enable AWS Trusted Advisor in all accounts and use AWS Config rules with automatic remediation for findings from GuardDuty, Inspector, and Macie.

    Why it's wrong here

    Trusted Advisor provides best-practice checks but does not aggregate GuardDuty, Inspector, or Macie findings. AWS Config rules evaluate resource configuration and cannot ingest those detection service findings directly. Automatic remediation in Config applies to Config rules, not to third-party security findings, so this combination does not meet the aggregation requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.