Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud operations team manages 200 Amazon EC2 instances spread across three AWS accounts. They must continuously assess the instances for missing OS patches and misconfigured software, and they want findings aggregated in a single console with severity ratings and remediation runbooks. Which AWS service should the team deploy to meet these requirements?

⚠ Common exam trap

The trap here is assuming configuration-compliance services such as AWS Config or Trusted Advisor can see inside the guest operating system, when only a host-based vulnerability scanner like Amazon Inspector inventories installed packages and patches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Inspector

Continuous detection of missing OS patches and software misconfigurations inside EC2 instances requires a vulnerability management service with host-level visibility. Amazon Inspector uses the SSM agent to inventory packages and network reachability, assigns severity, and supports multi-account aggregation through a delegated administrator, so findings from all three accounts appear in one console with remediation runbooks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor evaluates account-level best practices across cost, security, fault tolerance, and service limits, but it does not inventory installed OS packages on individual EC2 instances or report missing operating system patches. Its security checks cover things like open ports and public S3 permissions, so it cannot satisfy continuous per-instance software vulnerability assessment.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates them against rules, which helps detect drift such as an unencrypted volume or an open security group. However, it has no visibility into installed operating system packages or missing kernel patches inside an instance, so it cannot deliver the required vulnerability findings.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to surface malicious or anomalous activity. It does not inspect guest operating systems for missing patches or software misconfigurations, making it unsuitable for the continuous vulnerability assessment described.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector continuously scans EC2 instances using the Systems Manager agent to detect software vulnerabilities and unintended network exposure, then assigns severity ratings and aggregates findings centrally across accounts via AWS Organizations and delegated administrator. This directly matches the requirement for ongoing OS patch and misconfiguration assessment with consolidated findings and remediation guidance.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.