A retail company hosts its core inventory management system on a fleet of Amazon EC2 instances. The company's security policy requires automated, continuous assessments of these instances to identify software package vulnerabilities and unintended network paths that could lead to exposure. Which AWS service should the company use to automate these security assessments?
- AAmazon GuardDuty
- Amazon InspectorCevap
- CAWS CloudTrail
- DAWS Shared Infrastructure Support, as vulnerability scanning and patching of customer-configured EC2 operating systems is the sole responsibility of AWS
Cevap
Amazon Inspector
Amazon Inspector is the correct service because it provides automated, continuous vulnerability management. It scans Amazon EC2 instances, Amazon Elastic Container Registry (ECR) container images, and AWS Lambda functions for software vulnerabilities and unintended network exposure.
Adım Adım Çözüm
Anahtar Kavram
Automated host and container vulnerability scanning using Amazon Inspector
Tahmini Süre:1m 30s