Topic 1 Question 153
A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization.
The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads.
Which solution will meet these requirements?
Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.
Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers
Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.
Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers.
ユーザの投票
コメント(3)
- 正解だと思う選択肢: C
Host-based security for EC2 instances: Amazon Inspector is specifically designed for vulnerability scanning of Amazon EC2 instances.
Container security for ECR: Inspector also supports scanning container images stored in Amazon ECR.
Automatic deployment to all accounts: Configuring a delegated administrator for Inspector in the organization ensures automatic deployment of the scanning agent to all member accounts, including new ones.
Automatic scanning for new workloads: Enabling automatic scanning for new member accounts guarantees that any new EC2 instances or container images launched will be automatically scanned by Inspector.
👍 3aescudero512024/06/09 - 正解だと思う選択肢: C
C is correct. Amazon Inspector is designed to automatically discover and scan workloads for software vulnerabilities and unintended network exposure. Configuring a delegated administrator for Amazon Inspector ensures centralized management and deployment of the security solution across all member accounts, including new ones. It also ensures that new workloads are automatically scanned upon deployment.
👍 3navid13652024/08/03 - 👍 2Zek2024/05/14
シャッフルモード