nerdexam
Amazon

SCS-C03 · Question #64

A company needs to identify the root cause of security findings and investigate IAM roles involved in those findings. The company has enabled VPC Flow Logs, Amazon GuardDuty, and AWS CloudTrail…

The correct answer is A. Use Amazon Detective to investigate IAM roles and visualize findings. Amazon Detective is specifically designed to help security teams investigate and visualize the root cause of security findings. According to AWS Certified Security - Specialty documentation, Detective automatically aggregates and correlates data from GuardDuty, CloudTrail, and…

Submitted by manish99· Mar 6, 2026Incident Response

Question

A company needs to identify the root cause of security findings and investigate IAM roles involved in those findings. The company has enabled VPC Flow Logs, Amazon GuardDuty, and AWS CloudTrail. Which solution will meet these requirements?

Options

  • AUse Amazon Detective to investigate IAM roles and visualize findings.
  • BUse Amazon Inspector and CloudWatch dashboards.
  • CExport GuardDuty findings to S3 and analyze with Athena.
  • DUse Security Hub custom actions to investigate IAM roles.

How the community answered

(62 responses)
  • A
    76% (47)
  • B
    8% (5)
  • C
    13% (8)
  • D
    3% (2)

Explanation

Amazon Detective is specifically designed to help security teams investigate and visualize the root cause of security findings. According to AWS Certified Security - Specialty documentation, Detective automatically aggregates and correlates data from GuardDuty, CloudTrail, and VPC Flow Logs to provide interactive visualizations and timelines. Detective enables investigators to pivot from GuardDuty findings to IAM roles, API calls, network traffic, and resource behavior. This makes it the most efficient tool for understanding how IAM roles were used during suspicious activity. Amazon Inspector focuses on vulnerability assessment, not behavioral investigation. Security Hub aggregates findings but does not provide deep investigation graphs. Manual analysis with Athena requires significantly more effort. AWS guidance explicitly recommends Amazon Detective for root cause analysis and visualization of security incidents.

Topics

#Amazon Detective#GuardDuty findings#IAM role investigation#root cause analysis

Community Discussion

No community discussion yet for this question.

Full SCS-C03 Practice