Inspector automatically scans your workloads — EC2 instances and container images — for software vulnerabilities and unintended network exposure, then prioritizes the findings by risk.
Inspector vs GuardDuty
Inspector finds vulnerabilities (unpatched software, risky network paths) in your workloads. GuardDuty detects active threats and malicious behavior. Scan for CVEs / missing patches → Inspector; detect an attack in progress → GuardDuty.
Test yourself
A team needs to automatically scan their EC2 instances for known software vulnerabilities and unintended network exposure. Which service?
- Amazon GuardDuty
- Amazon Inspector
- AWS Config
- AWS Shield
👉 Click to reveal the answer & explanation
Correct answer: B. Inspector scans workloads for software vulnerabilities and network exposure and prioritizes them by risk. GuardDuty (A) detects active threats, not vulnerabilities; Config (C) checks configuration compliance; Shield (D) is DDoS protection.
Related topics
Amazon GuardDuty · Amazon Macie · AWS Config
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first