Trigger CodePipeline with EventBridge on new commits and alert from ECR image scan findings via EventBridge to SNS
A company has deployed a new platform that runs on Amazon Elastic Kubernetes Service (Amazon EKS). The new platform hosts web applications that users frequently update. The application developers build the Docker images for the applications and deploy the Docker images manually to the platform. The platform usage has increased to more than 500 users every day. Frequent updates, building the updated Docker images for the applications, and deploying the Docker images on the platform manually have all become difficult to manage. The company needs to receive an Amazon Simple Notification Service (Amazon SNS) notification if Docker image scanning returns any HIGH or CRITICAL findings for operating system or programming language package vulnerabilities. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The pipeline trigger must be EventBridge matching the CodeCommit repository events, because S3 object-created events are not emitted when a file is committed to a repository, so an S3 event would never fire (B rather than A). The scanning and alerting must come from ECR image scan events rather than GuardDuty, since the requirement is specifically about Docker image scanning findings for operating system and programming language package vulnerabilities, which is what ECR scanning reports (D rather than C). Basic scanning only reports on newly pushed images and is free, so it satisfies the stated requirement without the enhanced scanning cost.
Two capabilities are required. First, the manual build and deploy process must become automated, which is done by storing the Dockerfile and deployment files in CodeCommit, building a CodePipeline triggered by an EventBridge event on new commits, and adding a stage that starts the CodeBuild project that builds the image and pushes it to Amazon ECR. Second, the SNS notification must come from ECR image scanning, so the repository's scanning is enabled and an EventBridge rule on ECR image scan events notifies SNS when the finding-severity-counts parameter is greater than zero at CRITICAL or HIGH.
Using an Amazon S3 event to invoke the pipeline when the Dockerfile is committed (A) — S3 does not emit object-created events for objects written to CodeCommit, so this trigger would never fire; the repository must emit its own events, which EventBridge matches. Monitoring Amazon GuardDuty events with the finding-severity-counts parameter (C) — that parameter belongs to ECR image scan findings, not GuardDuty findings, and GuardDuty does not report operating system and language package vulnerabilities in container images. Scanning the Dockerfile itself in CodeBuild (E) — the requirement is to scan the built image for package vulnerabilities, not the Dockerfile source, so building only on a successful Dockerfile scan does not report image vulnerabilities.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario has two separate requirements. For automating the build and deploy pipeline, the Dockerfile and Kubernetes deployment files are stored in CodeCommit, an AWS CodePipeline is created, and Amazon EventBridge is used to invoke that pipeline when a newer version of the Dockerfile is committed, with a pipeline stage that initiates the CodeBuild project (B). CodeCommit emits repository events, so an EventBridge rule on the CodeCommit event source is what actually fires when a commit occurs. For the notification, a CodeBuild project builds the image and pushes it to Amazon ECR, basic scanning is turned on for the repository, and an EventBridge rule on Amazon ECR image scan events sends an event to an SNS topic when the finding-severity-counts parameter exceeds zero at CRITICAL or HIGH (D). ECR image scanning reports operating system and programming language package vulnerabilities, which is precisely what the requirement asks to be notified about, and basic scanning covers newly pushed images at no additional cost. B and D are the correct combination.Why the Other Options Are Wrong
A stores the files in CodeCommit and creates a pipeline but triggers it with an Amazon S3 event when a newer version of the Dockerfile is committed. S3 does not emit object-created events for objects written to CodeCommit, so an S3 event would never fire when the file is committed and the pipeline would never start. B replaces that trigger with EventBridge on the repository events, which does fire. C builds the image and pushes it to ECR correctly, but creates an EventBridge rule that monitors Amazon GuardDuty events and keys on the finding-severity-counts parameter. That parameter is specific to ECR image scan findings; GuardDuty does not report operating system or programming language package vulnerabilities inside container images, so this rule would never carry the required findings. E configures CodeBuild to scan the Dockerfile itself and to build the image only when that scan succeeds. Scanning the Dockerfile does not surface vulnerabilities in the operating system or language packages inside the built image, which is what the requirement asks to be alerted about, and this option also leaves the manual deployment workflow in place. B and D are correct.Community Comment Notes
Community voted B,D unanimously. jamesf and trungtd explained that B sets up the CodePipeline pipeline triggered by changes in the CodeCommit repository and that EventBridge ensures the pipeline is invoked whenever there is a new commit. inturist and limelight04 agreed with B and D. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →