A company has applications running on Amazon EC2 instances and needs to evaluate application vulnerabilities and identify infrastructure deployments that don’t follow best practices. Which AWS service should the company use?
Choose an answer
Tap an option to check your answer.
Correct answer: Amazon Inspector.
Why this is the answer
Amazon Inspector is the correct choice because it is a vulnerability management service that continuously scans AWS workloads for software vulnerabilities and unintended network exposure. This directly addresses the need to evaluate application vulnerabilities and identify infrastructure deployments that don't follow best practices. AWS Trusted Advisor provides recommendations across five pillars (cost optimization, performance, security, fault tolerance, and service limits) but doesn't perform deep vulnerability scanning of applications. AWS Config enables you to assess, audit, and evaluate the configurations of your AWS resources, which is about compliance with rules, not vulnerability scanning. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, focusing on ongoing threats rather than proactive vulnerability assessment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed