The company wants notifications if new vulnerabilities are discovered on EC2 instances and also needs an audit trail of all login activity on the instances. Which solution meets both needs?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Inspector to scan EC2 instances for vulnerabilities. Install the Amazon CloudWatch Agent to collect system logs and send login records to CloudWatch Logs..
Why this is the answer
Amazon Inspector is the dedicated AWS service for automated vulnerability management, making it the correct choice for scanning EC2 instances for vulnerabilities and providing notifications. The Amazon CloudWatch Agent can collect system logs, including login activity (e.g., from /var/log/secure on Linux), and send them to CloudWatch Logs, which serves as a centralized repository for audit trails. Incorrect options: AWS Systems Manager can manage instances but isn't primarily a vulnerability detection service like Inspector. Kinesis Agent is for streaming data, not the most direct or efficient way to centralize system logs for audit trails compared to CloudWatch Agent. While Systems Manager Agent is installed on instances, Systems Manager itself is not the primary service for vulnerability detection. CloudTrail records AWS API calls, not detailed system login activity within the instances themselves. CloudWatch is for monitoring metrics and logs, not for actively detecting vulnerabilities on instances. AWS Config tracks resource configuration changes, not system logs or vulnerability scans.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed