SCS-C02 exam dumps

SCS-C02 practice question 249 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 249

Select 2

Your organization uses Amazon Elastic Container Registry (Amazon ECR) to store container images and Amazon EC2 instances to run workloads. To comply with security requirements, you need to ensure that container images in Amazon ECR are scanned for vulnerabilities, and you also need to identify vulnerabilities in the software running on your EC2 instances. Which combination of AWS services should you use to meet these requirements?

  1. A

    Amazon Inspector to scan EC2 instances and enable ECR image scanning

  2. B

    Amazon ECR image scanning to automatically scan container images for vulnerabilities

  3. C

    AWS Systems Manager Patch Manager to detect vulnerabilities in EC2 instances

  4. D

    Amazon GuardDuty to scan container images and EC2 instances for vulnerabilities

  5. E

    Amazon Inspector to scan for vulnerabilities in EC2 instances and Amazon ECR container images

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirement of scanning vulnerabilities in both EC2 instances and Amazon ECR container images, the best solution is to use Amazon Inspector for EC2 instances and enable Amazon ECR image scanning. These services are designed to work together to address vulnerabilities in compute workloads comprehensively.

  • A. Correct.

    Correct: Amazon Inspector can scan EC2 instances for vulnerabilities and also integrates with Amazon ECR to enable container image scanning. This service is designed for identifying vulnerabilities in compute workloads.

  • B. Correct.

    Correct: Amazon ECR image scanning detects vulnerabilities in container images stored within the Amazon ECR service. This ensures that container images are secure before deployment.

  • C. Incorrect.

    Incorrect: AWS Systems Manager Patch Manager is used for managing operating system and software patches on EC2 instances, but it does not scan for vulnerabilities in container images or EC2 instances.

  • D. Incorrect.

    Incorrect: Amazon GuardDuty is a threat detection service that identifies malicious behavior but does not perform vulnerability scanning on container images or EC2 instances.

  • E. Incorrect.

    Incorrect: While Amazon Inspector does support both EC2 instance scanning and Amazon ECR image scanning, this option is misleading because the functionality is not combined in the way this option suggests.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam