Remediate Security Hub non-compliance near-real-time via Config rule, Security Hub custom action, and EventBridge-to-Lambda

Evaluate the compliance of AWS resources. Design and implement an incident response plan.
Answer Correct answer: A, C, D — a Config rule with Lambda, a Security Hub custom action wired to EventBridge, and an EventBridge rule invoking Lambda, remediating without SCP changes.

A security administrator has enabled AWS Security Hub for all the AWS accounts in an organization in AWS Organizations. The security team wants near-real-time response and remediation for deployed AWS resources that do not meet security standards. All changes must be centrally logged for auditing purposes. The organization has reached the quotas for the number of SCPs attached to an OU and SCP document size. The team wants to avoid making any changes to any of the SCPs. The solution must maximize scalability and cost-effectiveness. Which combination of actions should the security administrator take to meet these requirements? (Choose three.)

  1. Create an AWS Config custom rule to detect configuration changes to AWS resources. Create an AWS Lambda function to remediate the AWS resources in the delegated administrator AWS account. Correct Answer
  2. Use AWS Systems Manager Change Manager to track configuration changes to AWS resources. Create a Systems Manager document to remediate the AWS resources in the delegated administrator AWS account.
  3. Create a Security Hub custom action to reference in an Amazon EventBridge event rule in the delegated administrator AWS account. Correct Answer
  4. Create an Amazon EventBridge event rule to Invoke an AWS Lambda function that will take action on AWS resources. Correct Answer
  5. Create an Amazon EventBridge event rule to invoke an AWS Lambda function that will evaluate AWS resource configuration for a set of API requests and create a finding for noncompllant AWS resources.

Community Votes

ACD
67%
ADE
33%

67% of anonymous learners picked answer ACD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Security Hub findings can be wired to EventBridge through a custom action, and EventBridge rules in the delegated admin account invoke Lambda for remediation—this delivers near-real-time response without touching SCPs (whose quotas are already exhausted). A Config custom rule provides the detection of configuration drift, and the Lambda remediation work is centralized and auditable in the delegated admin account.

Security Hub is already on for the organization and the team wants near-real-time detection and remediation of resources that fail security standards, with centralized audit logging and no SCP changes. The approach: an AWS Config custom rule detects non-compliant configuration and a Lambda remediates it; a Security Hub custom action is referenced by an EventBridge rule in the delegated admin account; that EventBridge rule invokes a Lambda to take action on the resources. All actions run in the delegated administrator account and are logged centrally.

Relying on SCPs for prevention (explicitly prohibited—quotas hit). Or duplicating detection logic in option E, which re-evaluates configuration and creates findings already produced by Security Hub/Config; ACD keeps a clean detect (Config/A) → wire (C) → act (D) pipeline.

Community Discussion (7 comments)

adit 👍 8 Selected: ACD
acd are correct answer
aescudero51 👍 5 Selected: ADE
My answer is A. Create an AWS Config custom rule to detect configuration changes to AWS resources. Create an AWS Lambda function to remediate the AWS resources in the delegated administrator AWS account. My answer is D. Create an Amazon EventBridge event rule to Invoke an AWS Lambda function that will take action on AWS resources. My answer is E. Create an Amazon EventBridge event rule to invoke an AWS Lambda function that will evaluate AWS resource configuration for a set of API requests and create a finding for noncompllant AWS resources.
IPLogic 👍 1 Selected: ACD
Option A: Creating an AWS Config custom rule and a Lambda function for remediation is a good choice for detecting and responding to configuration changes. Option D: Using an EventBridge event rule to invoke a Lambda function is also a good choice for taking action on AWS resources based on events. Option E: While creating an EventBridge event rule to evaluate AWS resource configuration and create findings for non-compliant resources is useful, it does not directly address the need for near-real-time remediation. It focuses more on evaluation and logging rather than immediate action. By including Option C (Security Hub custom action), you ensure that Security Hub findings can trigger EventBridge rules, which then invoke Lambda functions for remediation. This creates a more integrated and automated response system, aligning with the requirement for near-real-time response and remediatio
723993f 👍 1
(A) for config rule creation which is the main detection of config change, this will generate a SecurityHub finding as mentioned in the question to be already enabled. (C) Security hub can invoke event bridge. (D) eventbridge can invoke lambda at which point we can do anything
VerRi 👍 3 Selected: ACD
I will go for ACD
nischal77777 👍 1 Selected: ADE
ADE is most correct answer
sema2232 👍 1
CDE are correct answers

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A provides detection via an AWS Config custom rule plus a Lambda for remediation in the delegated admin account. C creates a Security Hub custom action that EventBridge can reference, linking Security Hub findings into the event bus. D adds the EventBridge rule that invokes a Lambda to act on the resources. Together they form a near-real-time, centrally logged, scalable remediation pipeline that avoids SCP changes entirely.

Why the Other Options Are Wrong

B uses Systems Manager Change Manager, which is for managing planned change workflows, not real-time compliance remediation. E duplicates detection by having a Lambda re-evaluate configuration and create findings, overlapping with A's Config rule and adding unnecessary cost/complexity; ACD is the cleaner detect-and-remediate combination. The question forbids SCP changes, so any SCP-based prevention is out.

Community Comment Notes

Community favored A,C,D (67 votes) over A,D,E (33). Commenters described A as the Config-based detection, C as the Security Hub-to-EventBridge wiring, and D as the EventBridge-to-Lambda action. A minority picked ADE, arguing E adds detection, but ACD is the coherent pipeline.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide