nerdexam
Amazon

SCS-C02 · Question #419

A company runs workloads on Amazon EC2 instances. The company needs to continually scan the EC2 instances for software vulnerabilities and unintended network exposure. Which solution will meet these…

The correct answer is A. Use Amazon Inspector. Set the scan mode to hybrid scanning. Amazon Inspector is specifically designed to automatically scan Amazon EC2 instances for software vulnerabilities and unintended network exposure. By setting the scan mode to hybrid scanning, it combines continuous assessment for both vulnerabilities and network configuration…

Submitted by yaw92· Mar 6, 2026Infrastructure Security

Question

A company runs workloads on Amazon EC2 instances. The company needs to continually scan the EC2 instances for software vulnerabilities and unintended network exposure. Which solution will meet these requirements?

Options

  • AUse Amazon Inspector. Set the scan mode to hybrid scanning.
  • BUse Amazon GuardDuty. Enable the Malware Protection feature.
  • CUse Amazon Inspector. Enable the Malware Protection feature.
  • DUse Amazon GuardDuty. Enable the Runtime Monitoring feature.

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    4% (1)
  • C
    11% (3)
  • D
    7% (2)

Explanation

Amazon Inspector is specifically designed to automatically scan Amazon EC2 instances for software vulnerabilities and unintended network exposure. By setting the scan mode to hybrid scanning, it combines continuous assessment for both vulnerabilities and network configuration issues, ensuring a thorough evaluation of EC2 instances to identify potential security risks. This solution meets the requirement of continually scanning for vulnerabilities and network exposure.

Topics

#Amazon Inspector#vulnerability scanning#network exposure#EC2 instances

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice