exam questions

Exam AWS Certified Cloud Practitioner CLF-C02 All Questions

View all questions & answers for the AWS Certified Cloud Practitioner CLF-C02 exam

Exam AWS Certified Cloud Practitioner CLF-C02 topic 1 question 2 discussion

A company has deployed applications on Amazon EC2 instances. The company needs to assess application vulnerabilities and must identify infrastructure deployments that do not meet best practices.
Which AWS service can the company use to meet these requirements?

  • A. AWS Trusted Advisor
  • B. Amazon Inspector
  • C. AWS Config
  • D. Amazon GuardDuty
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nepton
Highly Voted 2 years ago
Amazon Inspector for Audit CloudWatch for monitoring Config for compliance
upvoted 25 times
...
BShelat
Highly Voted 1 year, 2 months ago
Selected Answer: B
Inspector is all about security assessments of AWS based applications and their configurations against known vulnerabilities. GuardDuty is all about continuously and automatically process different foundational data sources such as CloudTrail event logs, VPC flow logs and DNS logs to find potential security threat over an entire AWS account not just only with applications and it also uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning to identify unexpected, potentially unauthorized, and malicious activity within AWS environment. So as far as assessment is concerned Inspector is the right answer.
upvoted 13 times
...
sarat5646
Most Recent 1 day, 8 hours ago
Selected Answer: B
Amazon Inspector is specifically designed to assess application vulnerabilities and identify security issues in your EC2 instances and other AWS resources. It performs automated security assessments and checks for deviations from best practices, such as missing patches or insecure configurations.
upvoted 1 times
...
sarat5646
1 day, 8 hours ago
Selected Answer: B
Amazon Inspector is specifically designed to assess application vulnerabilities and identify security issues in your EC2 instances and other AWS resources. It performs automated security assessments and checks for deviations from best practices, such as missing patches or insecure configurations.
upvoted 1 times
...
Kostiantyn12
2 months, 3 weeks ago
Selected Answer: B
b is correct
upvoted 1 times
...
Julio19vp
2 months, 3 weeks ago
Selected Answer: B
B es la correcta
upvoted 1 times
...
Devon_Pakilaran
3 months, 1 week ago
Selected Answer: D
Because Amazon guarduty must deployment to cloud trail
upvoted 1 times
...
1507a4f
3 months, 3 weeks ago
Selected Answer: B
The correct answer is: ✅ B. Amazon Inspector Explanation: Amazon Inspector is the AWS service designed to: Assess vulnerabilities in applications running on Amazon EC2 instances Automatically scan for software vulnerabilities and deviations from security best practices Integrate with AWS services like EC2, ECR, and Lambda to provide continuous scanning It is the most appropriate choice for identifying application-level security issues and misconfigurations on EC2. Why not the others? A. AWS Trusted Advisor: Checks for general best practices across AWS (cost, performance, limits, etc.), but not deep vulnerability scans. C. AWS Config: Tracks resource configuration compliance, not security vulnerabilities. D. Amazon GuardDuty: Detects threats and malicious activity, but doesn’t assess software/application vulnerabilities.
upvoted 1 times
...
junyao
3 months, 3 weeks ago
Selected Answer: B
i guess it by naming
upvoted 1 times
...
AyushPanwar
4 months, 3 weeks ago
Selected Answer: B
Amazon inspector Assess application vulnerabilities and Identify infrastructure misconfigurations and deviations
upvoted 1 times
...
quinlynrouxtheworld
4 months, 4 weeks ago
Selected Answer: B
B is the answer
upvoted 1 times
...
Kyniu
5 months, 2 weeks ago
Selected Answer: B
Amazon Inspector is a vulnerability management service designed to: • Automatically assess applications running on Amazon EC2 instances (and other compute environments like ECS with Fargate). • Scan for known vulnerabilities (CVEs) in software packages. • Evaluate the application and OS configurations against security best practices. • Continuously monitor the environment and trigger automated assessments upon deployments or changes. 🔍 It directly addresses both parts of the requirement: “assess application vulnerabilities” and “identify infrastructure that doesn’t meet best practices”.
upvoted 1 times
...
elijahmugariri
6 months, 1 week ago
Selected Answer: A
A is correct
upvoted 1 times
...
Dats1987
6 months, 1 week ago
Selected Answer: B
It is a correct answer
upvoted 1 times
...
ultraOriginalVillain
6 months, 2 weeks ago
Selected Answer: B
For people saying it is A) Trusted Advisor, the documentation for it Never mentions vulnerabilties. In the context of vulnerabiltirs the question is asking about security best practices therefore it is Inspector as that is a security focused product.
upvoted 1 times
ultraOriginalVillain
6 months, 2 weeks ago
B) Inspector is a newer service, it started with EC2 specifically then expanded to many more services. It needs to be enabled per organisation and per account as well. Whereas A) Trusted advisor is enabled by default but for Free (Basic) and Develop you only get 52 or 56 checks which you must refresh manually or use like CloudTrail API to refresh it on demand, for the others like Business or higher support it does some 490 checks for you automatically. The keywords unique for B) Inspector only === are vulnerabilities and security and compliance across AWS environments
upvoted 1 times
ultraOriginalVillain
6 months, 2 weeks ago
Inspector can for example search for CVEs IDs, usefull if you have like gear from the marketplace like a palo alto virtual firewall It's scoring is also correlated to and similar to CVE scoring. They sound similar but are actually ground and sky difference between the two services !!!
upvoted 1 times
...
...
...
foxewa
6 months, 2 weeks ago
Selected Answer: B
Amazon Insepector is an automated security assessment service that scans EC2 instances for vulnerabilities and assesses applications for exposure, vulnerabilities, and deviations from best practices.
upvoted 1 times
...
Roroyoshi
6 months, 3 weeks ago
Selected Answer: B
Inspector - audit Cloud watch - monitoring Config - compliance
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...