1Threat Detection and Incident Response
- 1.1Threat Detection
Understand threat detection—GuardDuty, Inspector, Macie, Detective, and IAM Access Analyzer. Find threats, vulnerabilities, and sensitive-data exposure from logs and activity.
- 1.2Aggregating Findings and Automated Response
Understand detection-to-response—Security Hub, EventBridge, auto-remediation (Lambda/SSM Automation), and isolation. Centralize findings and respond fast and mechanically.
- 1.3Incident Response Preparation and Forensics
Understand IR readiness—playbooks/runbooks, forensics (snapshots/isolation), CloudTrail trails, compromised-credential response, and least-privilege IR roles. Prepare in advance to respond fast and reliably.
- 1.4In-scope services for threat detection and incident response
A roundup of in-scope SCS-C03 services for threat detection and incident response.

