Centralize pre-scan and post-scan ECR repositories in the shared account and gate promotion with one EventBridge-triggered Lambda
A company is migrating its container-based workloads to an AWS Organizations multi-account environment. The environment consists of application workload accounts that the company uses to deploy and run the containerized workloads. The company has also provisioned a shared services account for shared workloads in the organization. The company must follow strict compliance regulations. All container images must receive security scanning before they are deployed to any environment. Images can be consumed by downstream deployment mechanisms after the images pass a scan with no critical vulnerabilities. Pre-scan and post-scan images must be isolated from one another so that a deployment can never use pre-scan images. A DevOps engineer needs to create a strategy to centralize this process. Which combination of steps will meet these requirements with the LEAST administrative overhead? (Choose two.)
Community Votes
58% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The least-overhead design centralizes both repository sets in one account (A) rather than scattering pre-scan repositories across every publishing account, and uses a single event-driven Lambda (E) rather than a CodePipeline per repository. The physical separation between pre-scan and post-scan repositories is what guarantees a deployment can never pull an unscanned image, since the organization policy grants write only to pre-scan and read only from post-scan. Option D would require creating and maintaining a separate CodePipeline for every pre-scan repository.
To centralize container image scanning with the least administrative overhead, create the pre-scan and post-scan Amazon ECR repositories in the shared services account, enable ECR image scanning on push to the pre-scan repositories, and use resource-based policies granting the organization write access to pre-scan and read access to post-scan so no deployment can consume unscanned images. A single AWS Lambda function reacting to ECR image scan completed events inspects the scan status and promotes only images without critical vulnerabilities into the post-scan repositories.
Creating a separate AWS CodePipeline for each pre-scan repository (D) — this multiplies pipeline definitions, one per repository, which is precisely the administrative overhead the question asks to avoid; trungtd highlighted this when explaining why E is preferred over D. Creating pre-scan repositories in each publishing account (B) — this distributes the scanning surface across accounts instead of centralizing it, and the option's policy only grants read access to the shared post-scan repositories. Option C's replication approach conflicts with the requirement that images be scanned before they reach the post-scan repositories.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Creating both the pre-scan and post-scan ECR repositories in the shared services account (A) centralizes the process in one place rather than scattering scanning across every application account. Enabling image scanning on push to the pre-scan repositories means every image is evaluated as it arrives, and resource-based policies that grant the organization write access to pre-scan repositories and read access only to post-scan repositories structurally guarantee that a deployment cannot consume a pre-scan image. A single Lambda function (E) reacting to ECR image scan completed events reads the scan status and pushes only images with no critical vulnerabilities into the post-scan repositories, so one function serves every repository with no per-repository pipeline to build or maintain.Why the Other Options Are Wrong
B creates pre-scan repositories in each account that publishes images, which distributes the scanning surface across accounts rather than centralizing it, and its resource-based policies grant only read access to the shared post-scan repositories without giving the publishing accounts the write access they would need. C configures replication from each pre-scan repository to its post-scan counterpart, which would copy images regardless of scan outcome and therefore does not gate deployment on a clean scan. D creates a separate CodePipeline for each pre-scan repository; while it does implement the scan-then-promote logic, it requires a pipeline definition per repository, which is the administrative overhead the question asks to minimize. A and E are the correct combination.Community Comment Notes
Community was split, A,E (58) versus A,D (42). The A,E camp argued that creating the repositories in the shared services account and using one Lambda minimizes overhead, and that D means creating and managing many pipelines. The A,D camp pointeded out operational concerns, with aws_god noting Lambda is not intended for Docker workloads and auxwww linking a discussion on building and pushing Docker images from Lambda. Both answers share A; the deciding factor is that D scales linearly with the number of repositories while E scales with a single function.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →