Soru

Zorluk: ZorThreat Detection and Vulnerability Management

A smart-agriculture IoT company runs containerized data processing applications on Amazon EC2 instances and stores container images in Amazon Elastic Container Registry (Amazon ECR). The security team wants to implement continuous, automated scans to identify software vulnerabilities in both the EC2 operating system packages and the ECR container images. According to the AWS Shared Responsibility Model, which AWS service performs these scans, and who is responsible for configuring the tool and remediating the findings?

  1. A
    Amazon GuardDuty is used to perform the vulnerability scans, and the customer is responsible for configuring the service and patching the identified vulnerabilities.
  2. Amazon Inspector is used to perform the vulnerability scans, and the customer is responsible for configuring the scans and patching the identified vulnerabilities.Cevap
  3. C
    Amazon Inspector is used to perform the vulnerability scans, and AWS is responsible for automatically applying patches to the EC2 instances and ECR container images.
  4. D
    AWS CloudTrail is used to scan the host operating systems and container images for vulnerabilities, and the customer is responsible for setting up trails and patching the systems.

Cevap

Amazon Inspector is used to perform the vulnerability scans, and the customer is responsible for configuring the scans and patching the identified vulnerabilities.
Amazon Inspector is a vulnerability management service that continuously scans AWS workloads, including Amazon EC2 instances and Amazon ECR container images, for software vulnerabilities and unintended network exposure. Under the AWS Shared Responsibility Model, the customer is responsible for configuring the service, analyzing the findings, and performing remediation (such as patching operating systems and updating container images), while AWS is responsible for the security OF the cloud (the underlying infrastructure).

Adım Adım Çözüm

1
Identify the security requirement from the scenario.
The platform needs continuous, automated scanning of Amazon EC2 operating system packages and Amazon ECR container images for known software vulnerabilities.
This establishes that the necessary capability is host and package vulnerability scanning rather than network threat detection or API activity logging.
2
Select the correct AWS service that corresponds to vulnerability scanning.
Amazon Inspector is identified as the AWS service that provides automated vulnerability management for EC2 and ECR.
This eliminates services like Amazon GuardDuty (used for threat detection) and AWS CloudTrail (used for API logging).
3
Apply the AWS Shared Responsibility Model to the scenario's operations.
Determine that while AWS provides the Amazon Inspector service, the customer is responsible for enabling it, configuring the scan scopes, analyzing the reports, and executing remediation actions such as patching the EC2 guest OS and updating container files.
This rules out the misconception that AWS automatically remediates or patches customer-managed software resources.

Anahtar Kavram

Vulnerability management and the division of security duties under the AWS Shared Responsibility Model
Tahmini Süre:2m 0s
Bu soruyu puanla