SCS-C02 Security Logging and Monitoring Practice Question
A security engineer is configuring Amazon Inspector to assess EC2 instances for software vulnerabilities. The engineer has installed the SSM Agent on all instances and ensured that the instances have internet access. However, Amazon Inspector shows the instances as 'Unmanaged'. What is the MOST likely cause?
⚠ Common exam trap
It's easy for candidates to assume internet access alone is sufficient for Inspector to work, overlooking the critical requirement that the SSM Agent must be actively running and registered with Systems Manager for the instance to be considered managed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SSM Agent is not running or is not registered with AWS Systems Manager.
Amazon Inspector requires EC2 instances to be managed by AWS Systems Manager (SSM) to install the SSM Agent and register it with the Systems Manager service. If the SSM Agent is not running or not registered, the instance cannot communicate with Systems Manager, and Inspector will report it as 'Unmanaged'. Even with internet access and the agent installed, the agent must be actively running and registered for the instance to be properly managed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM role attached to the EC2 instance does not have permissions to publish metrics to CloudWatch.
Why it's wrong here
Amazon Inspector does not rely on CloudWatch for assessment data collection or finding delivery, so lacking IAM permissions to publish CloudWatch metrics would not affect an instance's managed status. The instance's unmanaged status stems from the SSM Agent not being registered with AWS Systems Manager, not from missing CloudWatch access. Inspector sends findings to services like EventBridge and Security Hub, not CloudWatch metrics.
- ✗
The security group attached to the instance blocks outbound traffic to the Amazon Inspector service.
Why it's wrong here
A restrictive security group that blocks outbound traffic to AWS services could prevent the SSM Agent from reaching Systems Manager endpoints, but this would be an SSM connectivity issue, not the root cause of an 'Unmanaged' status in Inspector. Inspector itself does not have a directly contacted service endpoint on the instance; it relies on the SSM Agent's inventory channel. If the agent is not installed or registered, the instance is 'Unmanaged' regardless of security group rules.
- ✗
The instance does not have the EC2 instance metadata service enabled.
Why it's wrong here
The EC2 instance metadata service is not a prerequisite for Amazon Inspector assessment; Inspector does not query IMDS to determine managed status. While the SSM Agent uses instance metadata for credentials and instance identification, an unmanaged status in Inspector is caused by the agent not being installed or not registered with Systems Manager. Disabling IMDS would not by itself make an instance 'Unmanaged' if the SSM Agent is functional and uses another credential source.
- ✓
The SSM Agent is not running or is not registered with AWS Systems Manager.
Why this is correct
Amazon Inspector is integrated with AWS Systems Manager Agent, which is responsible for collecting inventory and system configuration data from EC2 instances for assessment. For an instance to appear as 'Managed,' the SSM Agent must be running and registered with the Systems Manager service. If the agent is not running or not registered, Inspector cannot obtain the necessary telemetry and therefore reports the instance as 'Unmanaged.' This is the correct condition that explains the issue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.