Set up an Inspector delegated administrator and enable automatic scanning for new member accounts
A company wants to implement host-based security for Amazon EC2 instances and containers in Amazon Elastic Container Registry (Amazon ECR). The company has deployed AWS Systems Manager Agent (SSM Agent) on the EC2 instances. All the company's AWS accounts are in one organization in AWS Organizations. The company will analyze the workloads for software vulnerabilities and unintended network exposure. The company will push any findings to AWS Security Hub, which the company has configured for the organization. The company must deploy the solution to all member accounts, including new accounts, automatically. When new workloads come online, the solution must scan the workloads. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Inspector is purpose-built for EC2/ECR vulnerability and unintended-network-exposure scanning and integrates with Security Hub; a delegated administrator plus 'auto-enable new accounts' gives org-wide, self-extending coverage with no per-account manual setup. SCPs (A) cannot configure scanning; GuardDuty (B) detects threats, not software vulnerabilities; an Config rule (D) does not initiate Inspector ECR analysis like the delegated-admin auto-scan does. C is correct.
For organization-wide host-based vulnerability and network-exposure scanning of EC2 and ECR, with findings to Security Hub and automatic coverage of new accounts and new workloads, configure a delegated administrator for Amazon Inspector and enable automatic scanning for new member accounts. Inspector discovers and scans EC2 and ECR automatically and publishes to the org's Security Hub.
Using SCPs (A) to 'configure scanning'—SCPs are permission guardrails, they cannot turn on Inspector scanning. Choosing GuardDuty (B)—it is threat detection, not vulnerability/CVE scanning of hosts and containers. An AWS Config rule (D) is not how Inspector auto-scans new ECR containers.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.