🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your security team must implement weekly vulnerability scans on more than 200 Amazon EC2 instances deployed across several VPCs. Host-based firewalls block most inbound traffic, and the team wants to avoid opening additional ports or creating extra inter-VPC network flows. Which solution satisfies the requirement while following AWS best practices for vulnerability management?

  • Export CloudTrail logs to Amazon Athena each day and run SQL queries to identify vulnerable software packages manually.

  • Turn on Amazon GuardDuty; its threat detection findings will include missing patches and software vulnerabilities on the EC2 fleet.

  • Enable Amazon Inspector for all EC2 instances so the existing SSM agent can perform agent-based vulnerability assessments without opening inbound ports.

  • Deploy a dedicated EC2 scanner in each VPC and schedule weekly nmap sweeps of every instance after allowing TCP ports 1-65535 through host firewalls.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot