AnswerCorrect answer: D — enable ECS Exec with SSM task-role permissions to inspect the running Fargate container with least effort.
A company deploys its application as a service on an Amazon Elastic Container Service (Amazon ECS) cluster with theAWS Fargate launch type. A security engineer suspects that some incoming requests are malicious. The security engineer needs to inspect the running container by retrieving log files and memory dump flies. Which solution will meet these requirements with the LEAST operational effort?
Migrate the application to an ECS cluster with the Amazon EC2 launch type. Configure the EC2 instances with proper remote access. Log in and inspect the container.
Update the application to dump the required data to STDOUT. Use the awslogs log driver to pass the logs to Amazon CloudWatch Logs. Examine the log files in CloudWatch Logs.
Turn on Amazon CloudWatch Container Insights for the ECS cluster. Send the log data to Amazon CloudWatch Logs by using AWS Distro for OpenTelemetry. Examine the log data in CloudWatch Logs.
Update the ECS task role with AWS Systems Manager permissions. Enable the ECS Exec feature for the ECS service. Use ECS Exec to inspect the container. Correct Answer
Community Votes
D
64%
B
36%
64% of anonymous learners picked answer D.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
ECS Exec provides direct, least-privilege command execution inside a running Fargate task through Session Manager, needing only the task role to have SSM permissions. It avoids the operational cost of switching to EC2 launch type or modifying the application to emit logs to STDOUT, and it can reach artifacts (like memory dumps) that are not exposed via logging alone.
A security engineer suspects malicious requests to an ECS Fargate service and needs to inspect the running container, retrieving log and memory-dump files. Enabling ECS Exec on the service and updating the task role with Systems Manager permissions lets the engineer run commands directly inside the running container over a secure channel, retrieving files without migrating off Fargate or rewriting the application.
Migrating to EC2 launch type (option A) just to get shell access, or rewriting the app to dump everything to STDOUT/CloudWatch (option B). B cannot surface arbitrary files such as memory dumps and requires application changes; ECS Exec is the lower-effort path.
Community Discussion (6 comments)
IPLogic👍 1Selected: D
Keywording in question - Least operational overhead Option D fits this...
gkaself👍 1Selected: D
D is correct
lanjr01👍 2
Answer: D - see link below https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-exec.html
matheusrdo👍 2Selected: D
The question asks to inspect the container and retrieve files, so ECS Exec sounds reasonable.
aescudero51👍 4Selected: B
My answer is B. https://docs.aws.amazon.com/whitepapers/latest/replatform-dotnet-apps-with-windows-containers/logging-and-monitoring.html
5409b91👍 3Selected: D
Option D is the most efficient solution as it allows for direct and secure access to the container's runtime environment without significant modifications to the application or infrastructure setup. It leverages existing AWS services and features, reducing operational overhead and complexity.
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
ECS Exec lets you open an interactive shell or run commands in a running Fargate container through a managed Session Manager channel. By enabling ECS Exec on the service and granting the task role the required Systems Manager permissions, the engineer can inspect the container and copy log or memory-dump files directly, with minimal infrastructure change and the least operational effort.
Why the Other Options Are Wrong
A requires migrating the workload to EC2 launch type and configuring remote access, a large operational change. B forces application modifications to redirect data to STDOUT and cannot retrieve arbitrary files like memory dumps. C (Container Insights + OpenTelemetry) gives performance/telemetry metrics, not the ability to retrieve files from inside a container.
Community Comment Notes
Community was split D (64) vs B (36). D supporters cited the "least operational overhead" keyword and that ECS Exec is purpose-built to inspect a running container. B supporters linked a logging whitepaper but B needs app changes and cannot pull memory dumps.