ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 473 - CLF-C02 discussion

Report
Export

A company needs an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities.

Which AWS service will meet these requirements?

A.
Amazon GuardDuty
Answers
A.
Amazon GuardDuty
B.
Amazon Inspector
Answers
B.
Amazon Inspector
C.
AWS Security Hub
Answers
C.
AWS Security Hub
D.
AWS Shield
Answers
D.
AWS Shield
Suggested answer: B

Explanation:

The correct answer is B. Amazon Inspector.

Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure. Amazon Inspector automatically discovers workloads, such as Amazon EC2 instances, containers, and Lambda functions, and scans them for software vulnerabilities and unintended network exposure12.

Amazon GuardDuty is a threat detection service that monitors your AWS accounts and workloads for malicious or unauthorized activity. Amazon GuardDuty does not scan for software vulnerabilities, but rather analyzes AWS CloudTrail, Amazon VPC Flow Logs, and DNS logs to detect threats such as compromised credentials, backdoors, or crypto mining3.

AWS Security Hub is a security and compliance service that aggregates and prioritizes security findings from multiple AWS services and partner solutions. AWS Security Hub does not scan for software vulnerabilities, but rather provides a comprehensive view of your security posture across your AWS accounts4.

AWS Shield is a managed service that protects your web applications and network resources from distributed denial-of-service (DDoS) attacks. AWS Shield does not scan for software vulnerabilities, but rather provides detection and mitigation of DDoS attacks at the network and application layers5.

1: Automated Software Vulnerability Management - Amazon Inspector - AWS 3: [Amazon GuardDuty -- Intelligent Threat Detection Made Easy] 2: AWS Re-Launches Amazon Inspector with New Architecture and Features - InfoQ 4: [AWS Security Hub -- Unified Security and Compliance Center] 5: [AWS Shield -- Managed DDoS Protection]

asked 16/09/2024
Matthew Wood
22 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first