exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 658 discussion

Exam question from Amazon's AWS-SysOps
Question #: 658
Topic #: 1
[All AWS-SysOps Questions]

A workload has been moved from a data center to AWS. Previously, vulnerability scans were performed nightly by an external testing company. There is a mandate to continue the vulnerability scans in the AWS environment with third-party testing occurring at least once each month.
What solution allows the vulnerability scans to continue without violating the AWS Acceptable Use Policy?

  • A. The existing nightly scan can continue with a few changes. The external testing company must be notified of the new IP address of the workload and the security group of the workload must be modified to allow scans from the external company's IP range.
  • B. If the external company is a vendor in the AWS Marketplace, notify them of the new IP address of the workload.
  • C. Submit a penetration testing request every 90 days and have the external company test externally when the request is approved.
  • D. AWS performs vulnerability testing behind the scenes daily and patches instances as needed. If a vulnerability cannot be automatically addressed, a notification email is distributed.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 7 months ago
A should be correct https://aws.amazon.com/security/penetration-testing/ Effective immediately, AWS customers are welcome to carry out security assessments or penetration tests against their AWS infrastructure without prior approval for 8 services.
upvoted 14 times
karmaah
2 years, 7 months ago
Yes. True.. But depends on the services . they have 'approved services and Prohibited services.' Few requires to get approval for them too. Anyway the question not mentioned what kind of vulnerability scan and where do they want to test.
upvoted 1 times
smplysam
2 years, 7 months ago
A seems to be the right answer. They are saying that the "workload" has been moved from datacenter to AWS. My guess is that they are referring to the on-prem servers that are being moved to EC2 instances. Since EC2 is covered under permitted services, they should able to continue with the scans, as long as the Security Groups associated with those EC2s allow communication from the external company's IP range.
upvoted 1 times
...
...
...
albert_kuo
Most Recent 8 months, 3 weeks ago
Selected Answer: C
Amazon Web Services (AWS) has a formal process for conducting penetration tests on resources hosted within its environment, and it requires you to submit a penetration testing request for approval. This process ensures that security standards are maintained and unauthorized activities are prevented.
upvoted 1 times
...
RicardoD
2 years, 6 months ago
A is the answer
upvoted 1 times
...
Kimle
2 years, 6 months ago
why B is wrong , there's a "professional services" section in marketplace that offer security assessment
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
A. The existing nightly scan can continue with a few changes. The external testing company must be notified of the new IP address of the workload and the security group of the workload must be modified to allow scans from the external company's IP range.
upvoted 1 times
...
jackdryan
2 years, 7 months ago
I'll go with A
upvoted 2 times
...
MFDOOM
2 years, 7 months ago
A. The existing nightly scan can continue with a few changes. The external testing company must be notified of the new IP address of the workload and the security group of the workload must be modified to allow scans from the external company's IP range.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago