nerdexam
AmazonAmazon

SCS-C02 · Question #6

SCS-C02 Question #6: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #6. The question stem and answer options stay visible for context.

Submitted by salim_om· Mar 6, 2026

Question

A company has hundreds of AWS accounts in an organization in AWS Organizations. The company operates out of a single AWS Region. The company has a dedicated security tooling AWS account in the organization. The security tooling account is configured as the organization's delegated administrator for Amazon GuardDuty and AWS Security Hub. The company has configured the environment to automatically enable GuardDuty and Security Hub for existing AWS accounts and new AWS accounts. The company is performing control tests on specific GuardDuty findings to make sure that the company's security team can detect and respond to security events. The security team launched an Amazon EC2 instance and attempted to run DNS requests against a test domain, example.com, to generate a DNS finding. However, the GuardDuty finding was never created in the Security Hub delegated administrator account. Why was the finding was not created in the Security Hub delegated administrator account?

Options

  • AVPC flow logs were not turned on for the VPC where the EC2 instance was launched.
  • BThe VPC where the EC2 instance was launched had the DHCP option configured for a custom
  • CThe GuardDuty integration with Security Hub was never activated in the AWS account where the
  • DCross-Region aggregation in Security Hub was not configured.

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions