How it works...
While enabling the Inspector, we selected the frequency of inspection as weekly. We can also run it once manually. We selected the types of inspection on EC2 instances as both network assessments and host assessments. With network assessments, AWS performs a network configuration analysis to check for the ports that are reachable from outside the VPC. With network assessments, installing an agent is optional; however, with the agent, AWS will also find the processes that are reachable on the ports.
With host assessments, AWS checks for common vulnerabilities and exposures (CVE), performs host hardening (CIS benchmarks), and implements other security best practices. With host assessments, we need to install the Inspector agent ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access