Set up an Inspector delegated administrator and enable automatic scanning for new member accounts

Answer Correct answer: C — an Inspector delegated administrator with automatic scanning for new member accounts covers all accounts and new workloads.

A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization. The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads. Which solution will meet these requirements?

  1. Use SCPs to configure scanning of EC2 instances and ECR containers for all accounts in the organization.
  2. Configure a delegated administrator for Amazon GuardDuty for the organization. Create an Amazon EventBridge rule to initiate analysis of ECR containers
  3. Configure a delegated administrator for Amazon Inspector for the organization. Configure automatic scanning for new member accounts. Correct Answer
  4. Configure a delegated administrator for Amazon Inspector for the organization. Create an AWS Config rule to initiate analysis of ECR containers.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Inspector is purpose-built for EC2/ECR vulnerability and unintended-network-exposure scanning and integrates with Security Hub; a delegated administrator plus 'auto-enable new accounts' gives org-wide, self-extending coverage with no per-account manual setup. SCPs (A) cannot configure scanning; GuardDuty (B) detects threats, not software vulnerabilities; an Config rule (D) does not initiate Inspector ECR analysis like the delegated-admin auto-scan does. C is correct.

For organization-wide host-based vulnerability and network-exposure scanning of EC2 and ECR, with findings to Security Hub and automatic coverage of new accounts and new workloads, configure a delegated administrator for Amazon Inspector and enable automatic scanning for new member accounts. Inspector discovers and scans EC2 and ECR automatically and publishes to the org's Security Hub.

Using SCPs (A) to 'configure scanning'—SCPs are permission guardrails, they cannot turn on Inspector scanning. Choosing GuardDuty (B)—it is threat detection, not vulnerability/CVE scanning of hosts and containers. An AWS Config rule (D) is not how Inspector auto-scans new ECR containers.

Community Discussion (3 comments)

navid1365 👍 3 Selected: C
C is correct. Amazon Inspector is designed to automatically discover and scan workloads for software vulnerabilities and unintended network exposure. Configuring a delegated administrator for Amazon Inspector ensures centralized management and deployment of the security solution across all member accounts, including new ones. It also ensures that new workloads are automatically scanned upon deployment.
aescudero51 👍 3 Selected: C
Host-based security for EC2 instances: Amazon Inspector is specifically designed for vulnerability scanning of Amazon EC2 instances. Container security for ECR: Inspector also supports scanning container images stored in Amazon ECR. Automatic deployment to all accounts: Configuring a delegated administrator for Inspector in the organization ensures automatic deployment of the scanning agent to all member accounts, including new ones. Automatic scanning for new workloads: Enabling automatic scanning for new member accounts guarantees that any new EC2 instances or container images launched will be automatically scanned by Inspector.
Zek 👍 2
C. Correct https://docs.aws.amazon.com/inspector/latest/user/adding-member-accounts.html https://www.examtopics.com/discussions/amazon/view/110834-exam-aws-certified-security-specialty-topic-1-question-485/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Inspector is designed to automatically discover and scan EC2 instances and ECR container images for software vulnerabilities and unintended network exposure, and it integrates with Security Hub. Configuring a delegated administrator for the organization plus automatic scanning for new member accounts extends coverage to every account—including newly created ones—and to new workloads as they come online, meeting all requirements with managed automation.

Why the Other Options Are Wrong

A suggests SCPs to configure scanning, but SCPs are permission boundaries and cannot enable Inspector. B uses GuardDuty, which detects threats/behavior, not software vulnerabilities in EC2/ECR. D uses an AWS Config rule to initiate ECR analysis, which is not how Inspector auto-scans new containers. C is the correct managed approach.

Community Comment Notes

Community voted C (100). Commenters noted Inspector is purpose-built for EC2/ECR vulnerability and network-exposure scanning and that a delegated admin with auto-enable-new-accounts covers the org automatically. C confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide