A SOC receives a request from the cloud team to assess newly deployed IaaS workloads for misconfigured IAM roles, public storage buckets, and unnecessary network exposure. The scanner supports operating system, network, container, and cloud API methods. Which method should the analyst select to evaluate the cloud control-plane configuration and exposed resources?
Select an answer to reveal the explanation.
Short Explanation
Think of cloud API scanning like checking the landlord's paperwork for the building, not just the paint inside each apartment. You want the configuration, permissions, and public storage, so the guest OS scanner is the wrong lens here.
Full Explanation
Cloud-native API scanning uses cloud provider APIs to inventory and evaluate control-plane and resource-configuration data: IAM policies, storage bucket access settings, network security groups, encryption defaults, and public exposure. This method is appropriate when the risk is misconfiguration rather than missing patches, because the cloud provider owns the hypervisor and base image while the customer owns configuration, identity, and access. Authenticated operating system scanning checks guest patch levels, services, and local vulnerabilities; it cannot see whether an IAM role has excessive permissions or a bucket is publicly readable. Network port scanning can reveal reachable hosts and open ports, but it does not explain why they are exposed or whether cloud access controls are correct. Container image scanning evaluates software packages, secrets, and dependencies inside an image, which is useful for build pipelines but not for evaluating deployed cloud resource permissions. Exam caveat: on CS0-004, choose the scanning method that matches the asset ownership boundary and the artifact being assessed. Operational check: confirm the scanner has read-only cloud API credentials, then review a sample report for IAM, storage, and network configuration findings before running it across the subscription.