A Security Engineer has several thousand Amazon EC2 instances split across production and development environments. Each instance is tagged with its environment. The Engineer needs to analyze and patch all the development EC2 instances to ensure they are not currently exposed to any common vulnerabilities or exposures (CVEs) . Which combination of steps is the MOST efficient way for the Engineer to meet these requirements? (Choose two.)
A) Log on to each EC2 instance, check and export the different software versions installed, and verify this against a list of current CVEs.
B) Install the Amazon Inspector agent on all development instances. Build a custom rule package, and configure Inspector to perform a scan using this custom rule on all instances tagged as being in the development environment.
C) Install the Amazon Inspector agent on all development instances. Configure Inspector to perform a scan using this CVE rule package on all instances tagged as being in the development environment.
D) Install the Amazon EC2 System Manager agent on all development instances. Issue the Run command to EC2 System Manager to update all instances.
E) Use AWS Trusted Advisor to check that all EC2 instances have been patched to the most recent version of operating system and installed software.
Correct Answer:
Verified
Q263: A company is developing a mobile shopping
Q264: A security team is implementing a centralized
Q265: A company is developing an ecommerce application.
Q266: A company uses AWS CodePipeline for its
Q267: Auditors for a health care company have
Q269: An application has been written that publishes
Q270: A security engineer needs to build a
Q271: An organization has a multi-petabyte workload that
Q272: A public subnet contains two Amazon EC2
Q273: A security engineer has noticed an unusually
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents