Trigger CodePipeline with EventBridge on new commits and alert from ECR image scan findings via EventBridge to SNS

Answer Correct answer: B, D — trigger CodePipeline via EventBridge on CodeCommit events and notify SNS from ECR image scan findings.

A company has deployed a new platform that runs on Amazon Elastic Kubernetes Service (Amazon EKS). The new platform hosts web applications that users frequently update. The application developers build the Docker images for the applications and deploy the Docker images manually to the platform. The platform usage has increased to more than 500 users every day. Frequent updates, building the updated Docker images for the applications, and deploying the Docker images on the platform manually have all become difficult to manage. The company needs to receive an Amazon Simple Notification Service (Amazon SNS) notification if Docker image scanning returns any HIGH or CRITICAL findings for operating system or programming language package vulnerabilities. Which combination of steps will meet these requirements? (Choose two.)

  1. Create an AWS CodeCommit repository to store the Dockerfile and Kubernetes deployment files. Create a pipeline in AWS CodePipeline. Use an Amazon S3 event to invoke the pipeline when a newer version of the Dockerfile is committed. Add a step to the pipeline to initiate the AWS CodeBuild project.
  2. Create an AWS CodeCommit repository to store the Dockerfile and Kubernetes deployment files. Create a pipeline in AWS CodePipeline. Use an Amazon EventBridge event to invoke the pipeline when a newer version of the Dockerfile is committed. Add a step to the pipeline to initiate the AWS CodeBuild project. Correct Answer
  3. Create an AWS CodeBuild project that builds the Docker images and stores the Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository. Turn on basic scanning for the ECR repository. Create an Amazon EventBridge rule that monitors Amazon GuardDuty events. Configure the EventBridge rule to send an event to an SNS topic when the finding-severity-counts parameter is more than 0 at a CRITICAL or HIGH level.
  4. Create an AWS CodeBuild project that builds the Docker images and stores the Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository. Turn on enhanced scanning for the ECR repository. Create an Amazon EventBridge rule that monitors ECR image scan events. Configure the EventBridge rule to send an event to an SNS topic when the finding-severity-counts parameter is more than 0 at a CRITICAL or HIGH level. Correct Answer
  5. Create an AWS CodeBuild project that scans the Dockerfile. Configure the project to build the Docker images and store the Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository if the scan is successful. Configure an SNS topic to provide notification if the scan returns any vulnerabilities.

Community Votes

BD
100%

100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The pipeline trigger must be EventBridge matching the CodeCommit repository events, because S3 object-created events are not emitted when a file is committed to a repository, so an S3 event would never fire (B rather than A). The scanning and alerting must come from ECR image scan events rather than GuardDuty, since the requirement is specifically about Docker image scanning findings for operating system and programming language package vulnerabilities, which is what ECR scanning reports (D rather than C). Basic scanning only reports on newly pushed images and is free, so it satisfies the stated requirement without the enhanced scanning cost.

Two capabilities are required. First, the manual build and deploy process must become automated, which is done by storing the Dockerfile and deployment files in CodeCommit, building a CodePipeline triggered by an EventBridge event on new commits, and adding a stage that starts the CodeBuild project that builds the image and pushes it to Amazon ECR. Second, the SNS notification must come from ECR image scanning, so the repository's scanning is enabled and an EventBridge rule on ECR image scan events notifies SNS when the finding-severity-counts parameter is greater than zero at CRITICAL or HIGH.

Using an Amazon S3 event to invoke the pipeline when the Dockerfile is committed (A) — S3 does not emit object-created events for objects written to CodeCommit, so this trigger would never fire; the repository must emit its own events, which EventBridge matches. Monitoring Amazon GuardDuty events with the finding-severity-counts parameter (C) — that parameter belongs to ECR image scan findings, not GuardDuty findings, and GuardDuty does not report operating system and language package vulnerabilities in container images. Scanning the Dockerfile itself in CodeBuild (E) — the requirement is to scan the built image for package vulnerabilities, not the Dockerfile source, so building only on a successful Dockerfile scan does not report image vulnerabilities.

Community Discussion (6 comments)

limelight04 👍 2 Selected: BD
The answer is BD
jamesf 👍 3 Selected: BD
Option B: - AWS CodeCommit repository to store the Dockerfile and Kubernetes deployment files. - Amazon EventBridge event to invoke the pipeline when a newer version of the Dockerfile is committed. Option D: - AWS CodeBuild project that builds the Docker images and stores the Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository. - enhanced scanning for the ECR repository.
tgv 👍 2
---> BD
trungtd 👍 4 Selected: BD
B sets up a CI/CD pipeline with AWS CodePipeline triggered by changes in the AWS CodeCommit repository. Using Amazon EventBridge ensures that the pipeline is invoked whenever there is a new commit, automating the build and deployment process. D ensures that Docker images are built and pushed to ECR, where enhanced scanning is enabled. Enhanced scanning provides detailed vulnerability information. An EventBridge rule is configured to monitor scan events and trigger notifications via SNS when HIGH or CRITICAL vulnerabilities are found.
inturist 👍 3 Selected: BD
Agree with B,D
tgv 👍 2
--> B D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario has two separate requirements. For automating the build and deploy pipeline, the Dockerfile and Kubernetes deployment files are stored in CodeCommit, an AWS CodePipeline is created, and Amazon EventBridge is used to invoke that pipeline when a newer version of the Dockerfile is committed, with a pipeline stage that initiates the CodeBuild project (B). CodeCommit emits repository events, so an EventBridge rule on the CodeCommit event source is what actually fires when a commit occurs. For the notification, a CodeBuild project builds the image and pushes it to Amazon ECR, basic scanning is turned on for the repository, and an EventBridge rule on Amazon ECR image scan events sends an event to an SNS topic when the finding-severity-counts parameter exceeds zero at CRITICAL or HIGH (D). ECR image scanning reports operating system and programming language package vulnerabilities, which is precisely what the requirement asks to be notified about, and basic scanning covers newly pushed images at no additional cost. B and D are the correct combination.

Why the Other Options Are Wrong

A stores the files in CodeCommit and creates a pipeline but triggers it with an Amazon S3 event when a newer version of the Dockerfile is committed. S3 does not emit object-created events for objects written to CodeCommit, so an S3 event would never fire when the file is committed and the pipeline would never start. B replaces that trigger with EventBridge on the repository events, which does fire. C builds the image and pushes it to ECR correctly, but creates an EventBridge rule that monitors Amazon GuardDuty events and keys on the finding-severity-counts parameter. That parameter is specific to ECR image scan findings; GuardDuty does not report operating system or programming language package vulnerabilities inside container images, so this rule would never carry the required findings. E configures CodeBuild to scan the Dockerfile itself and to build the image only when that scan succeeds. Scanning the Dockerfile does not surface vulnerabilities in the operating system or language packages inside the built image, which is what the requirement asks to be alerted about, and this option also leaves the manual deployment workflow in place. B and D are correct.

Community Comment Notes

Community voted B,D unanimously. jamesf and trungtd explained that B sets up the CodePipeline pipeline triggered by changes in the CodeCommit repository and that EventBridge ensures the pipeline is invoked whenever there is a new commit. inturist and limelight04 agreed with B and D. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide