ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 68 - DOP-C02 discussion

Report
Export

A company is performing vulnerability scanning for all Amazon EC2 instances across many accounts. The accounts are in an organization in AWS Organizations. Each account's VPCs are attached to a shared transit gateway. The VPCs send traffic to the internet through a central egress VPC. The company has enabled Amazon Inspector in a delegated administrator account and has enabled scanning for all member accounts.

A DevOps engineer discovers that some EC2 instances are listed in the 'not scanning' tab in Amazon Inspector.

Which combination of actions should the DevOps engineer take to resolve this issue? (Choose three.)

A.
Verify that AWS Systems Manager Agent is installed and is running on the EC2 instances that Amazon Inspector is not scanning.
Answers
A.
Verify that AWS Systems Manager Agent is installed and is running on the EC2 instances that Amazon Inspector is not scanning.
B.
Associate the target EC2 instances with security groups that allow outbound communication on port 443 to the AWS Systems Manager service endpoint.
Answers
B.
Associate the target EC2 instances with security groups that allow outbound communication on port 443 to the AWS Systems Manager service endpoint.
C.
Grant inspector:StartAssessmentRun permissions to the IAM role that the DevOps engineer is using.
Answers
C.
Grant inspector:StartAssessmentRun permissions to the IAM role that the DevOps engineer is using.
D.
Configure EC2 Instance Connect for the EC2 instances that Amazon Inspector is not scanning.
Answers
D.
Configure EC2 Instance Connect for the EC2 instances that Amazon Inspector is not scanning.
E.
Associate the target EC2 instances with instance profiles that grant permissions to communicate with AWS Systems Manager.
Answers
E.
Associate the target EC2 instances with instance profiles that grant permissions to communicate with AWS Systems Manager.
F.
Create a managed-instance activation. Use the Activation Code and the Activation ID to register the EC2 instances.
Answers
F.
Create a managed-instance activation. Use the Activation Code and the Activation ID to register the EC2 instances.
Suggested answer: A, B, E

Explanation:

https://docs.aws.amazon.com/inspector/latest/user/scanning-ec2.html

asked 16/09/2024
Anne Grethe Knutsen
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first