Courseiva

SCS-C02 Management and Security Governance Practice Question

A company wants to run a security assessment that checks for vulnerabilities in an EC2 instance. Which AWS service should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Inspector

Amazon Inspector automatically assesses EC2 instances for vulnerabilities and network exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector is a vulnerability management service that automatically scans Amazon EC2 instances, container images in Amazon ECR, and Lambda functions for software vulnerabilities and unintentional network exposure. It assesses the OS and application packages against known CVE databases and CIS benchmarks, producing a risk score. This is precisely the security assessment tool suited for checking compute workloads for weaknesses.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF is a layer-7 web application firewall that filters and monitors HTTP(S) traffic to protect resources like CloudFront, API Gateway, and Application Load Balancers from exploits such as SQL injection and cross-site scripting. It does not inspect OS-level packages, patch levels, or configuration drift on EC2 instances. Since it only reacts to live web traffic, it cannot perform the kind of point-in-time vulnerability assessment the company is requesting.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management events, VPC Flow Logs, and DNS query logs to identify unauthorized behavior or malicious activity. It relies on anomaly detection and threat intelligence to highlight active threats but does not enumerate installed software versions or search for CVEs. Therefore, while it improves security posture, it is not a vulnerability scanning service.

  • ✗

    AWS Shield Advanced

    Why it's wrong here

    AWS Shield Advanced is a managed DDoS mitigation service that provides always-on traffic monitoring and automatic inline mitigations for AWS resources, along with 24/7 access to the DDoS Response Team. It is designed for availability and to minimize downtime during volumetric attacks, not to detect or assess system-level weaknesses. Unlike a vulnerability scanner, Shield Advanced does not inspect the software stack for known vulnerabilities or misconfigurations.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.