SAA-C03 Design Secure Architectures Practice Question
An organization needs to perform continuous security assessments of its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which service should they use to automate these assessments and provide a centralized view of the findings?
⚠ Common exam trap
Candidates often choose AWS Config or Trusted Advisor. While helpful, these do not perform deep vulnerability scanning of the operating system and installed software packages like Inspector does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Inspector to automatically discover and scan EC2 instances for vulnerabilities.
Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure. It is particularly effective for EC2 instances as it can scan both the operating system and the installed applications, providing detailed findings and remediation advice to improve the security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor to check for security groups that allow unrestricted access.
Why it's wrong here
AWS Trusted Advisor provides a set of checks across several categories, including security. While it can identify broad issues like open ports, it does not perform deep software vulnerability scanning or continuous assessments of the internal state of EC2 instances, making it less comprehensive than Amazon Inspector.
- ✓
Amazon Inspector to automatically discover and scan EC2 instances for vulnerabilities.
Why this is correct
Amazon Inspector provides automated, continuous vulnerability scanning for EC2 instances and container images. It uses a unified findings format and integrates with AWS Security Hub, making it the standard choice for organizations looking to automate their vulnerability management and maintain a high level of security compliance.
- ✗
AWS CloudTrail to monitor and log all API calls made to the EC2 instances.
Why it's wrong here
AWS CloudTrail is a logging service that records API activity across your AWS infrastructure. While it is essential for auditing and identifying who performed an action, it does not scan for vulnerabilities in software or evaluate the network configuration against security best practices, which is the role of Inspector.
- ✗
VPC Flow Logs to analyze traffic patterns and identify potential security threats.
Why it's wrong here
VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC. This data is useful for troubleshooting and detecting anomalous traffic, but it does not provide information about software vulnerabilities or the internal security configuration of the EC2 instances themselves.
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.