SCS-C02 exam dumps

SCS-C02 practice question 251 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 251

Select 2

Your organization is running a containerized application using Amazon Elastic Kubernetes Service (Amazon EKS). You are tasked with ensuring that both the container images stored in Amazon Elastic Container Registry (Amazon ECR) and the running Amazon EC2 instances are regularly scanned for vulnerabilities. Which combination of AWS services can help you achieve this goal?

  1. A

    Amazon Inspector to automatically scan EC2 instances for vulnerabilities.

  2. B

    Amazon ECR image scanning to identify vulnerabilities in container images stored in the registry.

  3. C

    AWS Shield Advanced to protect against distributed denial-of-service (DDoS) attacks on EC2 instances.

  4. D

    AWS Config to scan for vulnerabilities in EC2 instances and container images.

  5. E

    Amazon Macie to detect sensitive data in container images.

Show answer and explanation

Correct answers: A, B

Explanation

To secure both the container images in Amazon ECR and the running EC2 instances hosting the container workloads, you need to use Amazon Inspector for EC2 instance vulnerability scanning and Amazon ECR image scanning for identifying vulnerabilities in container images. These two services complement each other to provide comprehensive vulnerability management for your compute workloads.

  • A. Correct.

    Amazon Inspector is designed to scan EC2 instances and container workloads for vulnerabilities. It is a suitable solution for addressing the security of running instances.

  • B. Correct.

    Amazon ECR image scanning is specifically designed to identify vulnerabilities in container images stored in the Amazon ECR registry. This directly addresses the security of containerized workloads.

  • C. Incorrect.

    AWS Shield Advanced is a service focused on DDoS protection, not vulnerability scanning. It is not relevant to the given scenario.

  • D. Incorrect.

    AWS Config is a configuration compliance service. It does not scan for vulnerabilities in EC2 instances or container images.

  • E. Incorrect.

    Amazon Macie is a data classification and protection service that identifies sensitive data, but it does not scan for vulnerabilities in container images or EC2 instances.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam