A company runs workloads on Amazon EC2. The company needs continuous monitoring for software vulnerabilities and must display the findings in AWS Security Hub. No agents can be installed on the EC2 instances. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon Inspector, set the scan mode to hybrid scanning, and enable the Amazon Inspector integration in Security Hub..
Why this is the answer
The correct solution is to enable Amazon Inspector, set the scan mode to hybrid scanning, and enable the Amazon Inspector integration in Security Hub. Amazon Inspector is a vulnerability management service that can scan EC2 instances for software vulnerabilities. Hybrid scanning allows Inspector to scan instances without requiring an agent by analyzing network configurations and package lists. Integrating Inspector with Security Hub automatically sends vulnerability findings to Security Hub for centralized visibility. Using Security Hub to enable the AWS Foundational Security Best Practices standard only checks for compliance with AWS security best practices, not software vulnerabilities within instances. Enabling Amazon GuardDuty and initiating on-demand scans with GuardDuty Malware Protection focuses on malware detection and threat intelligence, not software vulnerability scanning. Using AWS Config managed rules to detect EC2 software vulnerabilities primarily checks for configuration compliance against predefined rules, not deep software vulnerability analysis within the operating system or applications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed