A cloud operations team wants Instana to automatically identify software packages running on monitored hosts that have known Common Vulnerabilities and Exposures (CVEs) and display their severity scores alongside the affected infrastructure components. Which Instana feature directly provides this capability?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Instana's Vulnerability Management feature continuously evaluates software packages discovered on monitored hosts against CVE databases such as the National Vulnerability Database and presents findings with CVE IDs, CVSS severity scores, and affected component details in a dedicated Security view. This is distinct from Infrastructure Compliance scanning, which evaluates host configuration settings against security benchmarks rather than correlating software inventory with CVE records. Smart Alerts and Custom Events do not natively perform CVE correlation against a vulnerability database.
Full explanation below image
Full Explanation
Instana's Vulnerability Management feature continuously evaluates software packages discovered on monitored hosts against CVE databases such as the National Vulnerability Database and presents findings with CVE IDs, CVSS severity scores, and affected component details in a dedicated Security view. This is distinct from Infrastructure Compliance scanning, which evaluates host configuration settings against security benchmarks rather than correlating software inventory with CVE records. Smart Alerts and Custom Events do not natively perform CVE correlation against a vulnerability database. The correct answer is 'Instana Vulnerability Management, which scans discovered software packages against CVE databases and surfaces findings with severity scores in the Security view'. The incorrect options — 'Infrastructure Compliance policies configured with custom rules that reference specific CVE identifiers', 'Smart Alerts configured with a software inventory change condition to flag newly installed packages', 'Custom Events triggered by a process detection rule that matches the names of processes known to be associated with vulnerable software versions' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 7: Security/Compliance domain of the IBM Instana Observability certification.