AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A security team wants to identify EC2 instances that have network paths accessible from the internet due to misconfigured security groups or route tables, in addition to scanning those instances for known software vulnerabilities. Which AWS service provides both network reachability analysis and vulnerability scanning?

  1. AAmazon GuardDuty
  2. BAmazon Inspector
  3. CAWS WAF
  4. DAWS Config
Show answer & explanation

Correct answer: B. Amazon Inspector

Amazon Inspector performs automated vulnerability assessments on EC2 instances and container images, and it also includes network reachability analysis to identify unintended internet accessibility caused by security group or routing misconfigurations.

Why the other options are wrong

  • A. GuardDuty detects threats from logs/network traffic, not reachability paths.
  • C. WAF filters web traffic; it doesn't assess network paths or vulnerabilities.
  • D. Config checks configuration compliance but does not scan for vulnerabilities.

Amazon Inspector Network Reachability

Amazon Inspector automatically assesses EC2 instances and ECR images for software vulnerabilities and unintended network exposure paths.

  • Combines CVE vulnerability scanning with network reachability checks
  • Continuously and automatically scans running EC2 instances
  • Also scans container images in Amazon ECR

Memory trick: Inspector checks both the lock (vulnerabilities) and the door (network path)

More Security and Compliance questions