Instiq
Chapter 1 · Threat Detection and Incident Response·v2.0.0·Updated 6/5/2026·~8 min

What's changed: Deepened SCS-C02 Chapter 1 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

1.4In-scope services for threat detection and incident response

Key points

A roundup of in-scope SCS-C03 services for threat detection and incident response.

1.4.1In-scope services for threat detection and incident response

For threat detection and incident response, beyond GuardDuty/Detective/Security Hub/Inspector, know these in-scope services: Amazon Security Lake (auto-centralize/normalize security logs/events into a dedicated S3 data lake using OCSF), Automated Forensics Orchestrator for Amazon EC2 (automate forensic acquisition of suspected EC2), AWS Fault Injection Service (validate incident-response/failover procedures via fault injection), and Amazon Application Recovery Controller (control safe multi-Region/AZ failover).

Diagram grouping aggregation (Security Lake / OCSF data lake), forensics (Automated Forensics Orchestrator for Amazon EC2), and validation/recovery (Fault Injection Service / Application Recovery Controller).
Threat detection/incident response services

1.4.2Section summary

  • Aggregate/forensics: Security Lake (OCSF data lake) / Automated Forensics Orchestrator for Amazon EC2
  • Validate/recover: Fault Injection Service / Application Recovery Controller

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which service auto-centralizes security logs/events into an S3 data lake and normalizes them with the OCSF schema?

Q2. Which solution automates evidence preservation (snapshot/isolation) of suspected EC2 instances?

Check your understandingPractice questions for Chapter 1: Threat Detection and Incident Response