For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 39
    Hard1 markMultiple Choice
    Domain 3.2: Security ImprovementSecurityGuardDutyEventBridgeIncident Response

    AWS SAP-C02 · Question 39 · Domain 3.2: Security Improvement

    A security team wants to automate the response to compromised Amazon EC2 instances. If Amazon GuardDuty detects that an EC2 instance is communicating with a known command-and-control (C&C) server, the instance must be immediately isolated from the network, and a forensic snapshot of its EBS volume must be taken. What is the MOST automated way to achieve this?

    Answer options:

    A.

    Use AWS Config rules to detect the GuardDuty finding and trigger an AWS Systems Manager Automation document.

    B.

    Create an Amazon EventBridge rule triggered by GuardDuty findings. Route the event to an AWS Step Functions state machine that isolates the instance via Security Groups and triggers an EBS snapshot.

    C.

    Configure Amazon Macie to monitor network traffic and trigger a Lambda function to isolate the instance.

    D.

    Write a cron job on a management instance to poll the GuardDuty API every 5 minutes and execute a bash script.

    How to approach this question

    Identify the event routing and orchestration services.

    Full Answer

    B.Create an Amazon EventBridge rule triggered by GuardDuty findings. Route the event to an AWS Step Functions state machine that isolates the instance via Security Groups and triggers an EBS snapshot.✓ Correct
    Amazon GuardDuty sends findings to Amazon EventBridge. EventBridge can trigger an AWS Step Functions state machine, which can orchestrate the complex workflow of changing Security Groups (isolation) and taking snapshots (forensics).

    Common mistakes

    Confusing AWS Config's purpose with EventBridge's real-time event routing.
    Question 38All questionsQuestion 40

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →