A company primarily uses EC2. The DevOps team needs to audit all EC2 instances for installation of prohibited applications. Which approach satisfies this requirement with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Install and configure AWS Systems Manager on each instance, enable Systems Manager Inventory, and create AWS Config rules that evaluate Inventory changes to detect prohibited applications..
Why this is the answer
The correct approach leverages AWS Systems Manager Inventory and AWS Config. Systems Manager Inventory automatically collects data about instances, including installed applications, with minimal configuration once the agent is installed. AWS Config can then continuously evaluate these inventory changes against predefined rules to identify prohibited applications, providing an automated and low-overhead auditing solution. The first incorrect option adds unnecessary complexity by introducing S3 and Lambda for analysis, which is less integrated than Config rules for continuous compliance. The third incorrect option misuses CloudTrail; CloudTrail logs API activity, not the detailed inventory data needed for application auditing. The fourth option involves significant operational overhead by requiring custom scripts and extensive CloudWatch Logs configuration for each instance, which is less efficient than Systems Manager Inventory.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed