A security engineer must design controls for Amazon EC2 instances in a VPC that process sensitive workloads. The solution must detect and remediate software vulnerabilities on the instances. Which approach satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Inspector to scan the EC2 instances. Apply security patches and updates by using AWS Systems Manager Patch Manager..
Why this is the answer
Amazon Inspector is a vulnerability management service that continuously scans AWS workloads for software vulnerabilities and unintended network exposure, making it ideal for detecting vulnerabilities on EC2 instances. AWS Systems Manager Patch Manager automates the patching process for operating systems and applications, directly addressing the remediation requirement. Installing host-based firewalls and antivirus software requires manual management and doesn't provide a centralized vulnerability scanning solution like Inspector. The CloudWatch agent is for collecting logs and metrics, not for vulnerability detection or patching. Amazon GuardDuty Malware Protection focuses on detecting malware, not general software vulnerabilities, and doesn't cover patching.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed