Question 486:
You are a DevOps engineer and manage an AWS account. Recently, a third party audit company has found that several EC2 instances in the ap-south-1 region have security vulnerabilities and are exposed to threats from outside. You need to set up a mechanism immediately in the AWS account to inspect the common vulnerabilities and exposures (CVEs) for all the EC2 instances in the ap-south-1 region. The check should be performed every day and generate a detailed list of security findings. Which method would you select?
Answer options:
A.Set up a 24 hours schedule in AWS Systems Manager Patch Manager to check the patching level, inspect the vulnerabilities and generate reports. B.In AWS Systems Manager Automation, select the common vulnerabilities and exposures (CVEs) automation document and set up a 24 hours schedule. C.Install the Amazon Inspector agent on every EC2 instance and Amazon Inspector will check common vulnerabilities and exposures (CVEs) automatically and generate a report in the AWS console. D.In Amazon Inspector, create an assessment with the Common Vulnerabilities and Exposures (CVEs) rule package and include all the EC2 instances in the AWS account and region. Run the assessment every 24 hours.