A school district wants continuous vulnerability visibility for Amazon EC2 instances and container images used by student-facing systems. Which service prescription best meets this need?
Select an answer to reveal the explanation.
Short Explanation
Student systems need a smoke alarm that stays on—not a yearly fire drill checklist. Amazon Inspector keeps scanning EC2 and images and pushes findings to the security team. VPN walls do not patch CVEs, and GameLift is not a vuln scanner (or even in scope here).
Full Explanation
Amazon Inspector provides automated vulnerability assessment for EC2 and container images, aligning with SAP-C02 Task 1.2 security visibility needs across organizational accounts. Findings can integrate with Security Hub and operational workflows for remediation. Manual spreadsheet-only processes and disabling scanning leave continuous exposure undetected; Amazon GameLift is out of scope for this exam and is not a vulnerability management solution.