exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 354 discussion

A company wants to automate the security assessment of its Amazon EC2 instances. The company needs to validate and demonstrate that security and compliance standards are being followed throughout the development process.
What should a solutions architect do to meet these requirements?

  • A. Use Amazon Macie to automatically discover, classify and protect the EC2 instances.
  • B. Use Amazon GuardDuty to publish Amazon Simple Notification Service (Amazon SNS) notifications.
  • C. Use Amazon Inspector with Amazon CloudWatch to publish Amazon Simple Notification Service (Amazon SNS) notifications
  • D. Use Amazon EventBridge (Amazon CloudWatch Events) to detect and react to changes in the status of AWS Trusted Advisor checks.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mahdeo01
Highly Voted 3 years, 7 months ago
1) Macie : Checks data patterns in S3 ( using AI ) like PII or other sensitive information 2) Inspector : Checks what happens when you actually get an attack. ( this is useful for Assessment ) ; Pro-active 3) GuardDuty : Analyzes the actual events that happened in the AWS that it is running. ( Reactive ) 4) EventBridge : AWS Serverless Service that helps to build event-driven applications
upvoted 58 times
...
dmscountera
Highly Voted 3 years, 8 months ago
C. Use Amazon Inspector with Amazon CloudWatch to publish Amazon Simple Notification Service (Amazon SNS) notifications
upvoted 15 times
...
queen101
Most Recent 2 years, 10 months ago
ccccccccccccc
upvoted 1 times
...
Alfene
2 years, 10 months ago
C is the right one
upvoted 1 times
...
marklovesaws143
2 years, 10 months ago
Selected Answer: C
CCCCCCCCCCCC
upvoted 1 times
...
slcheng
2 years, 11 months ago
Selected Answer: C
Vote C
upvoted 1 times
...
fefer92
3 years, 4 months ago
Selected Answer: C
Answer is C
upvoted 1 times
...
LETSGETIT
3 years, 5 months ago
C: Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices.
upvoted 7 times
...
[Removed]
3 years, 6 months ago
Option "B" is the best response to this scenario. Explanation: AWS Guard Duty is an automated threat-detection service that can be quickly enabled, does not require agents to be installed, and monitors unusual account usage using sources like AWS CloudTrail logs, DNS logs, and other sources. Keyword is "automate"
upvoted 2 times
LETSGETIT
3 years, 4 months ago
The use case is asking about compliance and security which makes Inspector the correct answer as it is specifically for compliance
upvoted 2 times
...
zaxzax292
3 years, 3 months ago
Probably not. I think GuardDuty itself cannot publish SNS. It still needs to be combined with CloudWatch to achieve this goal.
upvoted 1 times
...
...
alikingo
3 years, 6 months ago
Why not D?
upvoted 3 times
...
gargaditya
3 years, 6 months ago
Answer is C-Inspector. ====== Guard Duty: Aim is to analyze logs: -CloudTrail Logs: unusual API calls, unauthorized deployments -VPC Flow Logs: unusual internal traffic, unusual IP address -DNS Logs: compromised EC2 instances sending encoded data within DNS queries Can protect against CryptoCurrency attacks (has a dedicated “finding” for it). It uses Machine Learning. ========= Macie helps identify and alert you to sensitive data, such as personally identifiable information (PII). Applies only for S3. ========= Inspector is specific to EC2. -Provides Automated Security Assessments for EC2 instances. -Requires agent installation on EC2 for Host(vulnerability assessment/best practices) OR can do NW Assessment for EC2 without installing agent
upvoted 9 times
...
jkwek
3 years, 8 months ago
Answer is C. https://aws.amazon.com/inspector/
upvoted 6 times
...
syu31svc
3 years, 8 months ago
https://aws.amazon.com/inspector/: "Amazon Inspector security assessments help you check for unintended network accessibility of your Amazon EC2 instances and for vulnerabilities on those EC2 instances. Amazon Inspector assessments are offered to you as pre-defined rules packages mapped to common security best practices and vulnerability definitions. Examples of built-in rules include checking for access to your EC2 instances from the internet, remote root login being enabled, or vulnerable software versions installed. These rules are regularly updated by AWS security researchers." C for correct
upvoted 9 times
...
Atanu_M
3 years, 8 months ago
Yes, C - Inspector - STREAMLINE SECURITY COMPLIANCE It gives security teams and auditors visibility into the security testing that is being performed during development of applications on AWS. This streamlines the process of validating and demonstrating that security and compliance standards and best practices are being followed throughout the development process.
upvoted 5 times
...
waqas
3 years, 8 months ago
C is sure.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...