Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 95 Topic 10 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 95 Topic 10 Discussion

SCS-C02 Exam Topic 10 Question 95 Discussion:
Question #: 95
Topic #: 10

A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company hasdeployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The companywill analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub. which the company hasconfigured for the organization.

The company must deploy the solution to all member accounts, including pew accounts, automatically. When new workloads come online, the solution must scan theworkloads.

Which solution will meet these requirements?


A.

Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.


B.

Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers


C.

Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts.


D.

Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.