SCS-C02 Management and Security Governance Practice Question
A security team wants to centrally manage and automatically remediate findings across 40 AWS accounts in an organization. They need a solution that aggregates security findings from GuardDuty, Inspector, and Macie into one place and can trigger automated remediation runbooks. Which combination of services BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming AWS Config automatic remediation can act on GuardDuty, Inspector, or Macie findings, when Config remediation is scoped to Config rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.
Security Hub with organization integration ingests and normalizes findings from GuardDuty, Inspector, and Macie across all accounts, providing a single aggregation point. EventBridge rules can match Security Hub findings and invoke Systems Manager Automation runbooks for automated remediation. Trusted Advisor, Detective, and CloudTrail Lake do not aggregate these detection findings, and scheduled or S3-triggered remediation lacks native integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Amazon Detective in all accounts and forward findings to a central S3 bucket, then use AWS Lambda functions triggered by S3 event notifications for remediation.
Why it's wrong here
Amazon Detective helps investigate and analyze security findings but is not an aggregation service for GuardDuty, Inspector, and Macie. Forwarding findings to S3 and triggering Lambda on object creation adds latency and complexity, and does not provide the native normalization and cross-account aggregation that Security Hub offers for these sources.
- ✗
Enable AWS CloudTrail Lake in all accounts and create queries that detect GuardDuty, Inspector, and Macie findings, then use EventBridge Scheduler to run remediation scripts.
Why it's wrong here
CloudTrail Lake stores and queries CloudTrail events, not the findings generated by GuardDuty, Inspector, or Macie. Those services publish findings through their own APIs and Security Hub, not as CloudTrail management events. EventBridge Scheduler runs tasks on a schedule rather than reacting to findings, so remediation would not be event-driven.
- ✓
Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.
Why this is correct
Security Hub aggregates findings from GuardDuty, Inspector, and Macie across organization accounts when centralized configuration is enabled. EventBridge can match Security Hub findings and invoke Systems Manager Automation runbooks to remediate automatically. This combination provides both centralized aggregation and automated response, directly satisfying the stated requirements for 40 accounts.
- ✗
Enable AWS Trusted Advisor in all accounts and use AWS Config rules with automatic remediation for findings from GuardDuty, Inspector, and Macie.
Why it's wrong here
Trusted Advisor provides best-practice checks but does not aggregate GuardDuty, Inspector, or Macie findings. AWS Config rules evaluate resource configuration and cannot ingest those detection service findings directly. Automatic remediation in Config applies to Config rules, not to third-party security findings, so this combination does not meet the aggregation requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.