What's changed: Deepened SCS-C02 Chapter 1 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)
1.4In-scope services for threat detection and incident response
A roundup of in-scope SCS-C03 services for threat detection and incident response.
1.4.1In-scope services for threat detection and incident response
For threat detection and incident response, beyond GuardDuty/Detective/Security Hub/Inspector, know these in-scope services: Amazon Security Lake (auto-centralize/normalize security logs/events into a dedicated S3 data lake using OCSF), Automated Forensics Orchestrator for Amazon EC2 (automate forensic acquisition of suspected EC2), AWS Fault Injection Service (validate incident-response/failover procedures via fault injection), and Amazon Application Recovery Controller (control safe multi-Region/AZ failover).
1.4.2Section summary
- Aggregate/forensics: Security Lake (OCSF data lake) / Automated Forensics Orchestrator for Amazon EC2
- Validate/recover: Fault Injection Service / Application Recovery Controller
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which service auto-centralizes security logs/events into an S3 data lake and normalizes them with the OCSF schema?
Q2. Which solution automates evidence preservation (snapshot/isolation) of suspected EC2 instances?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

