AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company utilizes a multi-account AWS environment managed through AWS Organizations. The Chief Information Security Officer (CISO) has mandated a new initiative to enhance the security posture across all accounts. The primary goals are to establish a centralized dashboard for all security and compliance findings from services like Amazon GuardDuty and AWS Config, and to address two critical requirements:
Continuously and automatically scan all Amazon EC2 instances and container images in Amazon ECR for software vulnerabilities and unintended network exposure.
Proactively identify any resource-based policies (e.g., on S3 buckets or IAM roles) that grant access to external entities outside of their AWS Organization.
Which combination of AWS services should a solutions architect propose to meet all these requirements in the most integrated and efficient manner?
Deploy an AWS CloudTrail organization trail, and configure Amazon Detective and Amazon Inspector in all accounts.
Enable AWS Security Hub as a delegated administrator, and configure Amazon Inspector and AWS IAM Access Analyzer in all accounts.
Enable AWS Security Hub as a delegated administrator, and configure AWS Systems Manager Patch Manager and AWS IAM Access Analyzer in all accounts.
Enable AWS Security Hub as a delegated administrator, and configure Amazon Inspector and AWS Trusted Advisor in all accounts.
The correct solution is to enable AWS Security Hub, Amazon Inspector, and AWS IAM Access Analyzer.
AWS Security Hub provides a comprehensive and centralized view of your security posture across your AWS accounts. It aggregates, organizes, and prioritizes security findings from various AWS services like Amazon GuardDuty, AWS Config, Amazon Inspector, and AWS IAM Access Analyzer. Designating a delegated administrator in AWS Organizations allows for central management.
Amazon Inspector is the specific service designed for automated and continuous vulnerability management. It scans EC2 instances and container images in ECR for software vulnerabilities and unintended network exposure, directly meeting the first critical requirement.
AWS IAM Access Analyzer continuously monitors resource-based policies to identify resources shared with an external entity outside of your defined zone of trust (such as your AWS Organization). This directly addresses the second critical requirement to prevent unintended external access.
Incorrect options:
Using AWS Trusted Advisor instead of IAM Access Analyzer is incorrect because while Trusted Advisor provides security best practice checks, IAM Access Analyzer is the specialized tool that uses formal reasoning to continuously analyze policies for unintended external access.
Using AWS CloudTrail and Amazon Detective does not meet the requirements. CloudTrail is an audit log of API activity, and Detective is an investigation tool to analyze the root cause of findings. Neither service performs proactive vulnerability scanning or external access analysis.
Using AWS Systems Manager Patch Manager instead of Amazon Inspector is incorrect. Patch Manager is a remediation tool used to apply patches to instances, whereas Inspector is the service that performs the vulnerability scanning to identify which patches are needed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Security Hub and why is it important for a multi-account setup?
Open an interactive chat with Bash
How does Amazon Inspector protect against vulnerabilities in EC2 instances and ECR container images?
Open an interactive chat with Bash
What role does AWS IAM Access Analyzer play in securing resource-based policies?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access