The information security team wants Instana to automatically evaluate all discovered infrastructure components against security benchmark rules — such as verifying that SSH root login is disabled and that unused network services are not running — and surface any violations in a centralized view. Which Instana capability fulfills this requirement?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Instana's Infrastructure Compliance feature allows administrators to define and assign compliance policies based on security benchmarks, which are automatically evaluated against monitored infrastructure at regular intervals. Violations are reported in the Compliance dashboard with context about the affected host and the specific rule that failed. Vulnerability Management addresses software CVEs rather than host configuration benchmarks, making it a separate and complementary capability rather than a substitute for compliance scanning.
Full explanation below image
Full Explanation
Instana's Infrastructure Compliance feature allows administrators to define and assign compliance policies based on security benchmarks, which are automatically evaluated against monitored infrastructure at regular intervals. Violations are reported in the Compliance dashboard with context about the affected host and the specific rule that failed. Vulnerability Management addresses software CVEs rather than host configuration benchmarks, making it a separate and complementary capability rather than a substitute for compliance scanning. The correct answer is 'Infrastructure Compliance policies — define benchmark-based rules evaluated against discovered hosts and surface violations in the Compliance dashboard'. The incorrect options — 'Vulnerability Management — scans software packages on monitored hosts for CVE matches against the NVD database', 'Custom Events with a host configuration change trigger that fires whenever a configuration attribute drifts from a defined baseline', 'Smart Alerts with a multi-condition policy covering each benchmark check as a separate condition threshold' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 7: Security/Compliance domain of the IBM Instana Observability certification.