Courseiva

SCS-C02 · topic practice

Threat Detection and Incident Response practice questions

This domain covers detecting and responding to security events across AWS accounts using GuardDuty, Security Hub, Inspector, CloudTrail, Detective, and EventBridge. Questions present an incident scenario and ask you to choose the most efficient, scalable detection or automated response using native AWS services and Organizations-level aggregation.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Threat Detection and Incident Response

What the exam tests

What to know about Threat Detection and Incident Response

Be able to select the right detection source for a scenario and design scalable, automated response using Organizations, Security Hub aggregation, GuardDuty, and EventBridge with Lambda. The key is centralizing detection and response in the delegated administrator account rather than per-account tooling.

Centralizing GuardDuty, Security Hub, and Inspector findings across accounts via AWS Organizations delegated administrator

Using CloudTrail, VPC Flow Logs, and GuardDuty findings to investigate compromised EC2 instances and IAM credentials

Building automated responses with EventBridge rules, Lambda, and Systems Manager to isolate or remediate resources

Applying Amazon Detective and Security Hub insights to correlate findings and trace lateral movement during incidents

Watch out for

Common Threat Detection and Incident Response exam traps

  • ▸Choosing per-account manual remediation instead of Organizations-wide delegated administrator aggregation with Security Hub
  • ▸Relying on CloudTrail alone for network-level evidence when VPC Flow Logs or GuardDuty are needed
  • ▸Configuring EventBridge rules in each member account rather than centrally in the delegated administrator or security account

Practice set

Threat Detection and Incident Response questions

20 questions · select your answer, then reveal the explanation

During an incident response, a security engineer needs to collect memory and disk forensics from a running EC2 Windows instance without causing the instance to crash. The engineer has AWS Systems Manager SSM Agent installed. Which method should the engineer use?

A security engineer is investigating a potential data exfiltration incident. The engineer notices large volumes of data being transferred from an Amazon S3 bucket to an external IP address. Which AWS services can be used to detect and alert on such behavior? (Choose THREE.)

A company runs a critical web application on a fleet of EC2 instances behind an Application Load Balancer (ALB). The application uses an Aurora MySQL database. The security team receives an alert from Amazon GuardDuty that a specific EC2 instance is exhibiting behavior consistent with a cryptocurrency mining attack, including outbound connections to known mining pools. The instance is part of an Auto Scaling group that uses a launch template with a security group that allows outbound HTTPS traffic to 0.0.0.0/0. The security engineer needs to contain the incident while minimizing downtime for the application. The engineer has already taken a forensic snapshot of the instance's EBS volume. Which course of action should the engineer take next?

Match each AWS IAM policy type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Attached to a user, group, or role

Attached to a resource like S3 bucket

Maximum permissions for an identity

Used in AWS Organizations to restrict permissions

A company wants to ensure that any deleted CloudTrail logs are detected and alerted within minutes. Which approach should they use?

During incident response, a security engineer needs to capture network traffic from an EC2 instance for forensic analysis. The instance is part of an Auto Scaling group. Which action preserves the most evidence while minimizing disruption?

A security engineer is investigating a potential data exfiltration incident. The engineer suspects that an EC2 instance is sending data to an external IP address. Which TWO AWS services can provide evidence of outbound data transfer? (Select TWO.)

A company has enabled AWS CloudTrail and wants to receive real-time notifications when specific API calls, such as DeleteTrail, are made. Which service should be used to trigger an alert based on CloudTrail log events?

A company wants to ensure that all API calls made to AWS are logged for security analysis. Which TWO services can be used to achieve this? (Choose two.)

Refer to the exhibit. A security engineer reviews an S3 bucket policy that is intended to allow the root user of account 123456789012 to get objects only from the 10.0.0.0/24 IP range. However, the policy is not working as expected. What is the MOST likely reason?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789012:root"
      },
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/24"
        }
      }
    }
  ]
}
Question 11hardmultiple choice
Review the full subnetting walkthrough →

During an incident response, a security engineer needs to collect volatile data from an EC2 instance running Linux. The instance is in a private subnet with no direct internet access. The engineer has IAM permissions to use AWS Systems Manager Session Manager. Which command should the engineer use to capture memory and process information?

Refer to the exhibit. A security engineer is reviewing a resource-based policy attached to an AWS Lambda function. The engineer notices that the policy allows any Lambda function in the account to invoke the function. Which security concern should the engineer address?

Exhibit

Refer to the exhibit.
```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowLambdaInvocation",
      "Effect": "Allow",
      "Principal": {
        "Service": "lambda.amazonaws.com"
      },
      "Action": "lambda:InvokeFunction",
      "Resource": "arn:aws:lambda:us-east-1:123456789012:function:my-function"
    }
  ]
}
```

A security engineer is reviewing CloudTrail logs and notices API calls from an unknown IP address. The engineer needs to immediately block the IP address and receive alerts for any future suspicious activity. Which combination of actions should the engineer take?

A company uses AWS Organizations and has GuardDuty enabled in all accounts. The security team wants to suppress low-severity findings that are known false positives for a specific member account. How can this be achieved with minimal administrative overhead?

A security engineer is designing an incident response plan for a compromised S3 bucket. Which TWO actions should be taken to contain the incident? (Choose TWO.)

An organization is using Amazon EKS for container workloads. The security team wants to detect container escape attempts. Which THREE AWS services or features should be enabled? (Choose THREE.)

A company's security team is configuring Amazon GuardDuty to detect crypto-mining activities on EC2 instances. Which THREE indicators should the team monitor? (Choose 3.)

A security engineer notices that an EC2 instance is sending outbound traffic to a known malicious IP address. The instance is part of an Auto Scaling group behind an Application Load Balancer. The engineer needs to immediately stop the exfiltration while preserving forensic evidence. What is the BEST course of action?

A company uses AWS CloudTrail to log all API calls. The security team notices a series of `UpdateTrail` API calls from a user in the Security account, disabling logging on a multi-region trail. The user has a policy that allows `cloudtrail:UpdateTrail` only on trails with a specific tag. However, the trail does not have that tag. What is the MOST likely reason the call succeeded?

A security team is setting up incident response automation. Which TWO steps should be taken to ensure that a compromised EC2 instance is isolated while preserving forensic data? (Choose TWO.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Threat Detection and Incident Response sessions

Start a Threat Detection and Incident Response only practice session

Every question in these sessions is drawn from the Threat Detection and Incident Response domain — nothing else.

Related practice questions

Related SCS-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SCS-C02 exam test about Threat Detection and Incident Response?
Be able to select the right detection source for a scenario and design scalable, automated response using Organizations, Security Hub aggregation, GuardDuty, and EventBridge with Lambda. The key is centralizing detection and response in the delegated administrator account rather than per-account tooling.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Threat Detection and Incident Response questions in a focused session?
Yes — the session launcher on this page draws every question from the Threat Detection and Incident Response domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SCS-C02 topics?
Use the topic links above to move to related areas, or go back to the SCS-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SCS-C02 exam covers. They are not copied from any real exam or dump site.