A logistics provider runs a custom inventory application on a fleet of Amazon EC2 instances. The provider wants to implement automated checks to identify known software package vulnerabilities and unintended network exposure on these instances. According to the AWS Shared Responsibility Model, which statement correctly identifies the party responsible for configuring these checks, and the AWS service that should be utilized?
- The customer is responsible for securing their guest operating systems and applications, and they should use Amazon Inspector to perform the vulnerability scans.Cevap
- BAWS is responsible for maintaining the security of the guest operating system on EC2 instances, and AWS automatically performs these scans using Amazon Inspector.
- CThe customer is responsible for securing their guest operating systems and applications, and they should use Amazon GuardDuty to perform the vulnerability scans.
- DAWS is responsible for securing the customer's application dependencies, and AWS automatically monitors for vulnerabilities using AWS CloudTrail.
Cevap
The customer is responsible for securing their guest operating systems and applications, and they should configure Amazon Inspector to perform software package vulnerability and network exposure scans.
The correct option correctly identifies that under the AWS Shared Responsibility Model, the customer is responsible for the guest operating system and applications running on Amazon EC2. It also correctly specifies Amazon Inspector as the designated AWS service for scanning EC2 instances for software vulnerabilities and unintended network path exposure.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability scanning on Amazon EC2 falls under the customer's side of the Shared Responsibility Model and is performed using Amazon Inspector.
Tahmini Süre:1m 30s