Inspector Flashcards

This deck aims to help retain concepts related to the Amazon Inspector service. (15 cards)

1
Q

Which AWS automated vulnerability management service continuously scans workloads for software vulnerabilities and unintended network exposure?

A

Amazon Inspector

This deck covers Amazon Inspector Classic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which AWS services does Amazon Inspector assess for vulnerabilities and deviations from security best practices?

A
  • Amazon EC2
  • Amazon ECR
  • AWS Lambda
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How frequently can Amazon Inspector run vulnerability scans?

A

Scans can run as often as:
- 15 minutes
- 1 hour
- 1 day

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does Amazon Inspector produce after a scan completes?

A

A prioritized findings report, ordered by severity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What two assessment types does Amazon Inspector provide?

A
  • Network assessment: agent or agentless
  • Host assessment: requires an agent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which Amazon Inspector assessment type analyzes network configurations for unintentional exposure to the internet?

A

Network assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Amazon Inspector assessment type analyzes EC2 instances and container images for software vulnerabilities and configuration issues?

A

Host assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What collection of security rules does Amazon Inspector use to assess a security posture?

A

Rules packages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Amazon Inspector rules package analyzes end-to-end network reachability across EC2, ALB, Direct Connect, ELB, ENIs, Internet Gateway, NACLs, route tables, security groups, subnets, VPCs, VGWs, and VPC peering?

A

Network Reachability Rules Package

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What findings can the Network Reachability Rules Package return?

A
  • RecognizedPortWithListener
  • RecognizedPortNoListener
  • RecognizedPortNoAgent
  • UnrecognizedPortWithListener
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which Amazon Inspector rules packages require an agent?

A

Host rules packages:
- Common Vulnerabilities and Exposures (CVE)
- Center for Internet Security (CIS) Benchmark
- Security Best Practices for Amazon Inspector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What types of container image scanning does Amazon Inspector support?

A
  • Enhanced scanning
  • Basic scanning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does Amazon Inspector Enhanced Scanning provide?

A

Continuous scanning of container images for OS and programming language vulnerabilities, and event generation when new vulnerabilities are detected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does Amazon Inspector Basic Scanning work?

A

Performs scans on image push or manual trigger using the Common Vulnerabilities and Exposures (CVE) database from the open-source Clair project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What types of vulnerabilities are detected by Amazon Inspector Enhanced Scanning?

A

Operating system and programming language package vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly