AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A security auditor has identified that several Amazon EC2 instances in a company's AWS environment are running outdated operating systems and have open, unnecessary ports to the internet, creating significant security vulnerabilities. The company needs a service that can continuously assess their EC2 instances for software vulnerabilities and unintended network exposure. Which AWS service is designed to address this requirement?
- AAmazon GuardDuty
- BAmazon Inspector
- CAWS Security Hub
- DAWS WAF
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Inspector
Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. It automatically assesses Amazon EC2 instances for vulnerabilities (e.g., outdated OS, unpatched software) and unintended network exposure (e.g., open ports).
Why the other options are wrong
- A. Amazon GuardDuty is a threat detection service that monitors for malicious activity but does not perform vulnerability assessments of software or network configurations.
- C. AWS Security Hub aggregates security findings from various AWS services and partner products but does not perform the actual vulnerability assessment itself.
- D. AWS WAF is a web application firewall that protects against common web exploits, not for assessing EC2 instance vulnerabilities or network exposure.
Amazon Inspector
An automated security assessment service that helps improve the security and compliance of applications deployed on AWS by identifying vulnerabilities and deviations from best practices.
- Assesses EC2 instances for software vulnerabilities.
- Identifies unintended network exposure (e.g., open ports).
- Automated and continuous assessment.
- Generates detailed findings for remediation.
Memory trick: Inspector is the 'doctor' who checks your EC2 instances for 'sickness' (vulnerabilities).