Courseiva
DetectionmediumMultiple SelectObjective-mapped

SCS-C03 Detection Practice Question

An organization wants to improve its vulnerability management posture by ensuring that all Amazon EC2 instances are regularly scanned for software vulnerabilities and unintended network exposure. Which TWO features of Amazon Inspector help achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Continuous scanning for software vulnerabilities in installed packages.

Amazon Inspector is an automated vulnerability management service. It continuously scans EC2 instances for software vulnerabilities (using the SSM Agent) and network reachability issues. This dual approach ensures that both internal software flaws and external configuration weaknesses are identified and reported to the security team.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Continuous scanning for software vulnerabilities in installed packages.

    Why this is correct

    Amazon Inspector uses the AWS Systems Manager (SSM) Agent to collect the inventory of installed software on EC2 instances. It then automatically compares this inventory against known vulnerability databases (CVEs) to identify and report any software that requires patching or updates.

  • Network reachability analysis to detect open ports and exposure.

    Why this is correct

    The network reachability package in Amazon Inspector analyzes the VPC configuration, including Security Groups, Network ACLs, and Route Tables. It identifies whether instances have ports that are reachable from outside the VPC, helping to identify and close unintended paths of external access.

  • Automated remediation of insecure Security Group rules.

    Why it's wrong here

    Amazon Inspector is primarily a detection and assessment service. While it identifies network exposure, it does not automatically modify Security Group rules to remediate findings. Remediation must be handled through other services like AWS Config with SSM Automation or manual intervention.

  • Real-time detection of brute-force login attempts.

    Why it's wrong here

    Detecting active attacks like brute-force logins is the responsibility of Amazon GuardDuty, which analyzes VPC Flow Logs and CloudTrail. Inspector focuses on the 'state' of the resource (vulnerabilities and reachability) rather than monitoring live traffic for malicious behavioral patterns.

  • Malware scanning for EBS volumes attached to instances.

    Why it's wrong here

    Malware scanning for EBS volumes is a feature of Amazon GuardDuty (Malware Protection). Amazon Inspector focuses on software vulnerabilities in the operating system and applications, and network configuration issues, rather than scanning the file system for actual malware signatures or viruses.

About these practice questions

This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.