nerdexam
Amazon

SCS-C02 · Question #179

A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM…

The correct answer is C. Configure a delegated administrator for Amazon Inspector for the organization. Configure. https://docs.aws.amazon.com/inspector/latest/user/adding-member-accounts.html

Submitted by parkjh· Mar 6, 2026Threat Detection and Incident Response

Question

A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization. The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads. Which solution will meet these requirements?

Options

  • AUse SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the
  • BConfigure a delegated administrator for Amazon GuardDuty for the organization. Create an
  • CConfigure a delegated administrator for Amazon Inspector for the organization. Configure
  • DConfigure a delegated administrator for Amazon Inspector for the organization. Create an AWS

How the community answered

(57 responses)
  • A
    14% (8)
  • B
    7% (4)
  • C
    75% (43)
  • D
    4% (2)

Explanation

https://docs.aws.amazon.com/inspector/latest/user/adding-member-accounts.html

Topics

#Amazon Inspector#Organizations delegated admin#auto-enable#EC2 and ECR scanning

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice