Security, Identity, and Compliance
Amazon Inspector
An automated vulnerability-management service for supported workloads such as EC2 instances, container images, and Lambda functions.
Key points
- Inspector identifies software vulnerabilities and unintended network exposure for supported resources.
- Findings help prioritize remediation using vulnerability and resource context.
- Inspector does not replace network access controls or threat-activity detection.
Best-known use cases
- Find known package vulnerabilities in supported workloads.
- Continuously assess supported compute resources for exposure.
What candidates often confuse it with
- Inspector finds vulnerabilities; GuardDuty detects suspicious activity.
- Security Hub centralizes security posture and findings across services.
Key Cloud Practitioner takeaway
Known vulnerabilities and exposure point to Inspector, not GuardDuty.
Related services
- Amazon GuardDuty
- AWS Security Hub
Relevant exam tasks
- D2.2