Enable ECR enhanced scanning and use EventBridge with Lambda to reject images with HIGH or CRITICAL findings
A company needs to increase the security of the container images that run in its production environment. The company wants to integrate operating system scanning and programming language package vulnerability scanning for the containers in its CI/CD pipeline. The CI/CD pipeline is an AWS CodePipeline pipeline that includes an AWS CodeBuild build project, AWS CodeDeploy actions, and an Amazon Elastic Container Registry (Amazon ECR) repository. A DevOps engineer needs to add an image scan to the CI/CD pipeline. The CI/CD pipeline must deploy only images without CRITICAL and HIGH findings into production. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Both halves must be right: the scanner has to be enhanced scanning because basic scanning relies on the open-source Clair database and does not provide the coverage the requirement needs, and the verdict has to come from the Inspector scan status because that is what enhanced scanning produces (B and D). Option E is the trap, referencing the Clair scan status, which is the basic scanning implementation's engine and therefore pairs the wrong status with the wrong scanning mode (D).
The pipeline must block deployment of images carrying HIGH or CRITICAL findings in either operating system packages or language packages, and the check must cover both categories. Amazon ECR enhanced scanning is backed by Amazon Inspector and reports on a broader set of vulnerabilities with continuous rescanning, which is what makes it suitable for this gate. An EventBridge rule invokes a Lambda function when the image scan completes; the function reads the Amazon Inspector scan status and reports an Approved or Rejected verdict back to the pipeline, so a Rejected status stops the deployment.
Using Amazon ECR basic scanning (A) — tgv noted that basic scanning uses CVEs from the open-source Clair project while enhanced scanning integrates with Amazon Inspector, so basic scanning does not deliver the required vulnerability coverage for gating a production deployment. Having the Lambda function consume the Clair scan status (E) — Clair is basic scanning's engine, so consuming its status contradicts the use of enhanced scanning; the function must consume the Amazon Inspector scan status. Configuring ECR itself to submit a Rejected status to the pipeline (C) — ECR has no facility to report a verdict into a CodePipeline run, so the pipeline gate has to be driven by a separate component reacting to the scan completion event.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement has two parts that must be satisfied together. First, the scanning capability must cover both operating system and programming language package vulnerabilities: Amazon ECR enhanced scanning is integrated with Amazon Inspector and provides deeper, continuous vulnerability analysis than basic scanning, whose CVEs come from the open-source Clair project, so enhanced scanning is the correct choice (B). Second, the pipeline must be prevented from deploying images with CRITICAL or HIGH findings: an Amazon EventBridge rule is created to fire when the image scan completes, and the AWS Lambda function it invokes consumes the Amazon Inspector scan status and submits an Approved or Rejected status back to the CodePipeline, so a Rejected verdict halts the deployment before it reaches production (D). Pairing enhanced scanning with the Inspector status keeps the scanner and the status source consistent. B and D are the correct combination.Why the Other Options Are Wrong
A uses Amazon ECR basic scanning. As tgv observed, basic scanning draws its vulnerability data from the open-source Clair project, which does not provide the depth of coverage the requirement implies for a production deployment gate, whereas enhanced scanning is the Inspector-backed option. Note that option A pairs basic scanning with no gating mechanism at all, so images with HIGH or CRITICAL findings would not block deployment. C configures Amazon ECR to submit a Rejected status to the CI/CD pipeline when the scan returns CRITICAL or HIGH findings. ECR does not provide a facility to report a verdict into a CodePipeline execution; the gating decision must be made by a component reacting to the scan completion event, which is what the EventBridge rule and Lambda function in option D do. E creates an EventBridge rule and Lambda function but has the function consume the Clair scan status. Clair is the engine behind basic scanning, so consuming that status is inconsistent with the enhanced scanning in the correct answer and would not reflect the Inspector findings that matter. B and D are correct.Community Comment Notes
Community voted B,D unanimously. jamesf identified the keywords as ECR enhanced scanning, Amazon Inspector, and vulnerabilities, and explained that enhanced scanning is integrated with Inspector to provide thorough security checks. tgv drew the decisive distinction, noting from the documentation that basic scanning uses CVEs from the open-source Clair project while enhanced scanning integrates with Amazon Inspector, which is why D must consume the Inspector status rather than the Clair status. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →