AWS Solutions Architect Associate (SAA-C03) · Free practice question 11 of 12
Amazon Inspector vulnerability scanning
The security team at Penrose Logistics wants continuous, automated scanning of its EC2 instances and container images in Amazon ECR for known software vulnerabilities and unintended network exposure, with findings prioritized by severity. Which service should be enabled?
- A.AWS Shield Advanced
- B.AWS Security Token Service
- C.Amazon Inspector
- D.AWS Artifact
Show answer and explanation
Correct answer: C. Amazon Inspector
Why: Amazon Inspector automatically discovers and continuously scans EC2 instances, ECR container images, and Lambda functions for software vulnerabilities and network exposure, and it scores findings by risk. Shield Advanced protects against DDoS attacks, STS issues temporary credentials, and Artifact provides compliance reports.
More free AWS Solutions Architect Associate (SAA-C03) questions
- IAM explicit deny overrides allow
- VPC Flow Logs for connectivity troubleshooting
- Transit Gateway instead of peering mesh
- Scheduled scaling for predictable peaks
- RDS point-in-time restore
- Route 53 geolocation routing
- Data Lifecycle Manager for EBS snapshots
- DynamoDB Streams with Lambda
- Amazon MQ for broker migrations
- Graviton instances for price-performance
- Root user protection best practices