SCS-C02 Management and Security Governance Practice Question
A company wants to run a security assessment that checks for vulnerabilities in an EC2 instance. Which AWS service should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Inspector
Amazon Inspector automatically assesses EC2 instances for vulnerabilities and network exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon Inspector
Why this is correct
Amazon Inspector is a vulnerability management service that automatically scans Amazon EC2 instances, container images in Amazon ECR, and Lambda functions for software vulnerabilities and unintentional network exposure. It assesses the OS and application packages against known CVE databases and CIS benchmarks, producing a risk score. This is precisely the security assessment tool suited for checking compute workloads for weaknesses.
- ✗
AWS WAF
Why it's wrong here
AWS WAF is a layer-7 web application firewall that filters and monitors HTTP(S) traffic to protect resources like CloudFront, API Gateway, and Application Load Balancers from exploits such as SQL injection and cross-site scripting. It does not inspect OS-level packages, patch levels, or configuration drift on EC2 instances. Since it only reacts to live web traffic, it cannot perform the kind of point-in-time vulnerability assessment the company is requesting.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management events, VPC Flow Logs, and DNS query logs to identify unauthorized behavior or malicious activity. It relies on anomaly detection and threat intelligence to highlight active threats but does not enumerate installed software versions or search for CVEs. Therefore, while it improves security posture, it is not a vulnerability scanning service.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is a managed DDoS mitigation service that provides always-on traffic monitoring and automatic inline mitigations for AWS resources, along with 24/7 access to the DDoS Response Team. It is designed for availability and to minimize downtime during volumetric attacks, not to detect or assess system-level weaknesses. Unlike a vulnerability scanner, Shield Advanced does not inspect the software stack for known vulnerabilities or misconfigurations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.