SCS-C02 · Question #223
A company runs workloads on Amazon EC2 instances. The company needs to continually monitor the EC2 instances for software vulnerabilities and must display the findings in AWS Security Hub. The…
The correct answer is A. Enable Amazon Inspector. Set the scan mode to hybrid scanning. Enable the integration for. Amazon Inspector provides continuous vulnerability scanning for EC2 instances without requiring agents by utilizing the AWS Systems Manager (SSM) agent, which is often pre-installed on EC2 instances. By setting up Amazon Inspector and integrating it with AWS Security Hub…
Question
A company runs workloads on Amazon EC2 instances. The company needs to continually monitor the EC2 instances for software vulnerabilities and must display the findings in AWS Security Hub. The company must not install agents on the EC2 instances. Which solution will meet these requirements?
Options
- AEnable Amazon Inspector. Set the scan mode to hybrid scanning. Enable the integration for
- BUse Security Hub to enable the AWS Foundational Security Best Practices standard. Wait for
- CEnable Amazon GuardDuty. Initiate on-demand malware scans by using GuardDuty Malware
- DUse AWS Config managed rules to detect EC2 software vulnerabilities. Ensure that Security Hub
How the community answered
(42 responses)- A76% (32)
- B7% (3)
- C14% (6)
- D2% (1)
Explanation
Amazon Inspector provides continuous vulnerability scanning for EC2 instances without requiring agents by utilizing the AWS Systems Manager (SSM) agent, which is often pre-installed on EC2 instances. By setting up Amazon Inspector and integrating it with AWS Security Hub, vulnerability findings from Inspector can be displayed in Security Hub, meeting the company's requirements for monitoring without installing additional agents.
Topics
Community Discussion
No community discussion yet for this question.