exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 485 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 485
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization.

The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads.

Which solution will meet these requirements?

  • A. Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.
  • B. Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers.
  • C. Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.
  • D. Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Noexperience
1 year, 9 months ago
Selected Answer: D
D. Configure a delegated administrator for Amazon Inspector for the organisation. Create an AWS Config rule to initiate analysis of ECR containers.
upvoted 1 times
...
6_8ftwin
1 year, 11 months ago
Selected Answer: C
https://docs.aws.amazon.com/inspector/latest/user/designating-admin.html
upvoted 3 times
...
cloudenthusiast
2 years ago
Selected Answer: C
Amazon Inspector: Amazon Inspector is a security assessment service that helps analyze the behavior and configuration of applications running on EC2 instances. It can scan instances for common vulnerabilities and exposures (CVEs) and assess network exposure. Delegated administrator for Amazon Inspector: By configuring a delegated administrator for Amazon Inspector at the organization level, you can centrally manage and configure Inspector assessments for all member accounts. This allows you to automate the scanning process and ensure consistent security assessments across the organization. Automatic scanning for new member accounts: With the delegated administrator in place, you can configure automatic scanning for new member accounts. This ensures that any new workloads that come online in the organization's accounts are automatically scanned by Amazon Inspector for vulnerabilities and network exposure.
upvoted 3 times
...
Lekou2023
2 years ago
Correct Answer: C Amazon Inspector immediately discovers and scans AWS workloads for software vulnerabilities and unintended network exposure. Ref: https://aws.amazon.com/inspector/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...