ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your security team must implement weekly vulnerability scans on more than 200 Amazon EC2 instances deployed across several VPCs. Host-based firewalls block most inbound traffic, and the team wants to avoid opening additional ports or creating extra inter-VPC network flows. Which solution satisfies the requirement while following AWS best practices for vulnerability management?
Export CloudTrail logs to Amazon Athena each day and run SQL queries to identify vulnerable software packages manually.
Enable Amazon Inspector for all EC2 instances so the existing SSM agent can perform agent-based vulnerability assessments without opening inbound ports.
Turn on Amazon GuardDuty; its threat detection findings will include missing patches and software vulnerabilities on the EC2 fleet.
Deploy a dedicated EC2 scanner in each VPC and schedule weekly nmap sweeps of every instance after allowing TCP ports 1-65535 through host firewalls.
Amazon Inspector uses the pre-installed AWS Systems Manager (SSM) agent to collect software inventories and perform CVE assessments directly on the instance, so no inbound network access or scan engines are required. Running network scanners such as nmap would force every instance to expose ports and generate significant intra-VPC traffic. Amazon GuardDuty analyzes log data for threat indicators and does not perform patch or CVE checks, while querying CloudTrail for package events is manual and cannot be considered a reliable, scheduled vulnerability scan.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Amazon Inspector and how does it work for vulnerability scans?
Open an interactive chat with Bash
What is the AWS Systems Manager (SSM) agent, and why is it used for Amazon Inspector?
Open an interactive chat with Bash
Why are network-based scanning tools like nmap unsuitable for this scenario?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .