exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 867 discussion

Exam question from Amazon's AWS-SysOps
Question #: 867
Topic #: 1
[All AWS-SysOps Questions]

A company recently migrated from a third-party security application to Amazon Inspector. A sysops administrator discovered that a list of security findings is missing for some Amazon EC2 instances.
Which action will resolve this problem?

  • A. Generate the missing security findings list manually by logging in to the affected EC2 instances and running CLI commands.
  • B. Log in to the affected EC2 instances. Download and install the Amazon Inspector agent from AWS Marketplace on each instance.
  • C. Use a network reachability package to analyze network configurations to find security vulnerabilities on the affected EC2 instances.
  • D. Verify that the Amazon Inspector agent is installed and running on the affected instances. Restart the Amazon Inspector agent.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Reference:
https://docs.aws.amazon.com/inspector/latest/userguide/inspector_network-reachability.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jtzt2003
Highly Voted 1 year, 6 months ago
The answer is D. In order to search for EC2 vulnerabilities you need the agent installed and running.
upvoted 9 times
mrphuongbn
1 year, 6 months ago
I concur.
upvoted 1 times
...
...
waterzhong
Most Recent 10 months, 2 weeks ago
should be C. The rules in the Network Reachability package analyze your network configurations to find security vulnerabilities of your EC2 instances. The findings that Amazon Inspector generates also provide guidance about restricting access that is not secure.
upvoted 1 times
...
Finger41
10 months, 3 weeks ago
D - https://docs.aws.amazon.com/inspector/v1/userguide/inspector_installing-uninstalling-agents.html#install-linux I was initially thinking B, but you can use either Systems Manager or Install it via a "wget https://inspector-agent.amazonaws.com/linux/latest/install curl -O https://inspector-agent.amazonaws.com/linux/latest/install"
upvoted 1 times
...
aidenpearce01
1 year, 1 month ago
Selected Answer: D
i go with D , Inspector agent must installed first
upvoted 2 times
...
alexsandroe
1 year, 5 months ago
D. Verify that the Amazon Inspector agent is installed and running on the affected instances. Restart the Amazon Inspector agent.
upvoted 2 times
...
RicardoD
1 year, 5 months ago
D is the answer
upvoted 1 times
...
abhishek_m_86
1 year, 6 months ago
D. Verify that the Amazon Inspector agent is installed and running on the affected instances. Restart the Amazon Inspector agent. Seem correct
upvoted 2 times
...
kenkct
1 year, 6 months ago
B. Make sense that agent is missing and has to be installed. For D, it just do verification, it doesn't specify what to do if the agents were not installed on the instances, unless already mean "ensure" (sorry for my poor English, I could be wrong) D. Verify and "ensure" that the Amazon Inspector agent is installed and running on the affected instances. Restart the Amazon Inspector agent.
upvoted 1 times
khun
1 year, 6 months ago
You dont need to download Amazon Inspector agent from AWS Marketplace
upvoted 1 times
...
...
oscar_gdl
1 year, 6 months ago
B, some AMI does not have installed Amazon inspector, so you have to install it manually, so there EC2 does not have installled amazon inspector you have to log in to EC2 and install it. https://docs.aws.amazon.com/inspector/latest/userguide/inspector_installing-uninstalling-agents.html
upvoted 1 times
ittest2020
1 year, 6 months ago
You can not download Inspector Agent from AWS MArketplace. AWS Marketplace is used for getting softwares from vendors: https://aws.amazon.com/partners/aws-marketplace/ D is the correct answer
upvoted 4 times
...
...
jackdryan
1 year, 6 months ago
I'll go with D
upvoted 2 times
...
MFDOOM
1 year, 6 months ago
D. Verify that the Amazon Inspector agent is installed and running on the affected instances. Restart the Amazon Inspector agent.
upvoted 2 times
...
Newguru2020
1 year, 7 months ago
Ans: C What is the network reachability rules package? The network reachability rules package that identifies ports and services on your Amazon EC2 instances that are reachable from outside your VPC. When you run an assessment with this rules package, Inspector queries AWS APIs to read network configurations in your account such as Amazon Virtual Private Clouds (VPCs), security groups, network access control lists (ACLs), and route tables. then analyzes these network configurations to prove accessibility of ports. Findings show you the network configurations that allow access to a reachable port to help you easily restrict access as needed. The Amazon Inspector agent is not needed for assessments with the network reachability rules package. For instances with the Inspector agent installed, network reachability findings are enhanced with information that identifies which processes are listening on accessible ports.
upvoted 1 times
jtzt2003
1 year, 7 months ago
What does that have to do with the question? It doesn't state whether the vulnerabilities are network related or on the EC2. The answer is D.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago