Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

An organization uses AWS Organizations with multiple accounts. The security team needs a centralized location to collect and analyze security findings from GuardDuty, Inspector, and Macie. Which AWS service should they use?

⚠ Common exam trap

Candidates often confuse Amazon Detective’s investigative capabilities with Security Hub’s aggregation role, assuming Detective can centralize findings, when in fact Detective is a post-finding analysis tool that requires Security Hub or GuardDuty to provide the initial findings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Hub

AWS Security Hub is the correct service because it provides a centralized view of security alerts and compliance status across multiple AWS accounts. It aggregates findings from GuardDuty, Inspector, and Macie, normalizing them into the AWS Security Finding Format (ASFF), enabling the security team to analyze and prioritize threats in a single dashboard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Detective

    Why it's wrong here

    Amazon Detective focuses on investigative analysis after a potential issue is identified, using machine learning and prebuilt data aggregations to build behavioral graphs of resources and identities. It does not serve as the centralized multi-account aggregation hub that ingests, consolidates, and normalizes security alerts across AWS services such as GuardDuty, Inspector, and IAM Access Analyzer; that operational aggregation role belongs to AWS Security Hub.

  • ✓

    AWS Security Hub

    Why this is correct

    AWS Security Hub is the correct choice because it is purpose-built to aggregate security findings from AWS native services and third-party partner products into one place, while supporting multi-account architectures through a delegated administrator and cross-region finding aggregation. It consolidates alerts into the AWS Foundational Security Best Practices, CIS, and PCI DSS standards, and outputs normalized findings via the Security Finding Format API, making it the central command console for security status across the organization.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is primarily an operational monitoring service for metrics, logs, and alarms, such as EC2 CPU utilization or Lambda errors, rather than a security findings aggregator. Even though security-related events can be streamed into CloudWatch Logs or trigger CloudWatch Events/EventBridge, CloudWatch does not normalize or consolidate findings from multiple security services, so it cannot provide the single-pane-of-glass view required for multi-account security posture.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config captures resource configurations and configuration changes, and evaluates those configurations against managed or custom rules to produce compliance scores; its Config aggregator can combine compliance snapshot data across accounts and Regions. However, Config only understands infrastructure configuration and compliance, not variable threat findings like a GuardDuty finding or an Inspector vulnerability result, so it cannot aggregate security alerts from those services as Security Hub does.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.