Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A company needs to continuously scan Amazon EC2 instances for software vulnerabilities and unintended network exposure. Which AWS service should be used?

⚠ Common exam trap

Candidates often confuse Amazon Inspector with Amazon GuardDuty, mistakenly thinking GuardDuty performs vulnerability scanning when it actually focuses on threat detection from network and account activity, not on scanning EC2 instances for CVEs or network exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Inspector

Amazon Inspector is the correct service because it is specifically designed to automatically scan Amazon EC2 instances for software vulnerabilities (CVEs) and unintended network exposure (network reachability). It uses a combination of a managed agent (for OS-level assessment) and network configuration analysis to produce a detailed findings report, directly meeting the requirement for continuous scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration auditing and compliance service that records resource state changes and evaluates them against managed or custom rules. While it can detect non-compliant configurations such as overly permissive security groups or missing encryption, it does not inspect the underlying operating system, installed software packages, or CVEs. Therefore, AWS Config cannot identify software vulnerabilities or missing patches on EC2 instances.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector is purpose-built for vulnerability management, using an agent installed on EC2 instances to continuously collect telemetry about software packages, network configurations, and running processes. It correlates this data against a database of known Common Vulnerabilities and Exposures (CVEs) and performs network reachability checks to identify exposure of ports and protocols. This provides ongoing, deep scanning of software vulnerabilities and makes Inspector the correct choice.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides high-level best practice recommendations across five categories: cost optimization, performance, security, fault tolerance, and service limits. Its security checks focus on AWS-side configurations like open security groups, IAM usage, and root account MFA, but it never inspects the operating system, installed software, or patch levels of EC2 instances. Consequently, Trusted Advisor cannot perform continuous software vulnerability scanning.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS query logs using machine learning and threat intelligence to detect malicious activity like brute-force attacks, compromised credentials, or crypto mining. It does not deploy agents on EC2 instances and does not examine software packages or CVE databases. Thus, GuardDuty identifies active threats but does not scan for software vulnerabilities.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.