A company runs a fleet of Amazon EC2 instances that host a customer-facing web application. The security team wants to automatically identify software vulnerabilities, such as missing patches and common vulnerabilities and exposures (CVEs), in the operating system and applications running on these instances. The team also needs visibility into unintended network accessibility, such as instances with ports open to the internet. The solution must be natively integrated with AWS and should provide findings that can be viewed in a central dashboard. Which AWS service should the security team use?
Amazon Inspector is a vulnerability management service that automatically discovers EC2 instances and delivers software vulnerability (CVE) findings by scanning the operating system and installed packages, using data from AWS Systems Manager. It also maps network reachability of the instance to determine which vulnerabilities are actually exposed to the internet or a VPC, and assigns a severity and risk score for each finding. This allows the security team to prioritize patching based on real attack surface rather than just patch status.
Why this answer
Amazon Inspector is the correct choice because it is a vulnerability management service that automatically scans EC2 instances for software vulnerabilities (missing patches, CVEs) and unintended network accessibility (e.g., open ports to the internet). It is natively integrated with AWS and provides findings in a central dashboard via the AWS Management Console or AWS Security Hub. This directly matches the security team's requirements for automated identification of OS/application vulnerabilities and network exposure.
Exam trap
The trap here is that candidates often confuse Amazon GuardDuty (threat detection) with Amazon Inspector (vulnerability scanning), or assume AWS Security Hub performs the scanning itself rather than aggregating findings from other services.
Why the other options are wrong
Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior using network and account logs, but it does not perform vulnerability assessments for missing patches or CVEs in OS and applications.
AWS Security Hub aggregates and prioritizes security findings from multiple AWS services (like Inspector, GuardDuty) but does not itself perform vulnerability scanning or network accessibility checks. The question requires a service that directly identifies CVEs and open ports, which is Inspector's function.
AWS Trusted Advisor provides best-practice recommendations across cost, performance, security, and fault tolerance, but it does not perform automated vulnerability scanning for missing patches or CVEs in EC2 instances. It also lacks a central findings dashboard for software vulnerabilities.