Soru

Zorluk: KolayThreat Detection and Vulnerability Management

A gaming studio wants to automatically identify software vulnerabilities and unintended network exposure on its Amazon EC2 instances. Which AWS service should the studio use to perform these security assessments?

  1. Amazon InspectorCevap
  2. B
    Amazon GuardDuty
  3. C
    AWS CloudTrail
  4. D
    AWS Artifact

Cevap

Amazon Inspector
Amazon Inspector is the correct service because it automatically and continually scans workloads, including Amazon EC2 instances, for software vulnerabilities and unintended network exposure. It identifies package-level issues (CVEs) and provides actionable remediation recommendations.

Adım Adım Çözüm

1
Analyze the requirement to scan EC2 instances for software vulnerabilities and network exposure.
Identify that the task requires a vulnerability assessment tool for host operating systems and software packages.
This narrows down the choice to AWS security services that perform package-level and configuration-level vulnerability scanning.
2
Evaluate the capabilities of the available AWS services.
Determine that Amazon Inspector is designed for scanning software vulnerabilities, whereas GuardDuty is for active threat detection, CloudTrail is for API logging, and Artifact is for compliance documents.
Correctly matching the service definition guarantees selecting the proper tool for vulnerability management.

Anahtar Kavram

Vulnerability scanning for EC2 instances and workloads using Amazon Inspector
Tahmini Süre:45s
Bu soruyu puanla