Enable ECR enhanced scanning and use EventBridge with Lambda to reject images with HIGH or CRITICAL findings

Apply automation for security controls and data protection. Integrate automated testing into CI/CD pipelines.
Answer Correct answer: B, D — enable ECR enhanced scanning and reject the pipeline from a Lambda that reads the Amazon Inspector scan status.

A company needs to increase the security of the container images that run in its production environment. The company wants to integrate operating system scanning and programming language package vulnerability scanning for the containers in its CI/CD pipeline. The CI/CD pipeline is an AWS CodePipeline pipeline that includes an AWS CodeBuild build project, AWS CodeDeploy actions, and an Amazon Elastic Container Registry (Amazon ECR) repository. A DevOps engineer needs to add an image scan to the CI/CD pipeline. The CI/CD pipeline must deploy only images without CRITICAL and HIGH findings into production. Which combination of steps will meet these requirements? (Choose two.)

  1. Use Amazon ECR basic scanning.
  2. Use Amazon ECR enhanced scanning. Correct Answer
  3. Configure Amazon ECR to submit a Rejected status to the CI/CD pipeline when the image scan returns CRITICAL or HIGH findings.
  4. Configure an Amazon EventBridge rule to invoke an AWS Lambda function when the image scan is completed. Configure the Lambda function to consume the Amazon Inspector scan status and to submit an Approved or Rejected status to the CI/CD pipeline. Correct Answer
  5. Configure an Amazon EventBridge rule to invoke an AWS Lambda function when the image scan is completed. Configure the Lambda function to consume the Clair scan status and to submit an Approved or Rejected status to the CI/CD pipeline.

Community Votes

BD
100%

100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Both halves must be right: the scanner has to be enhanced scanning because basic scanning relies on the open-source Clair database and does not provide the coverage the requirement needs, and the verdict has to come from the Inspector scan status because that is what enhanced scanning produces (B and D). Option E is the trap, referencing the Clair scan status, which is the basic scanning implementation's engine and therefore pairs the wrong status with the wrong scanning mode (D).

The pipeline must block deployment of images carrying HIGH or CRITICAL findings in either operating system packages or language packages, and the check must cover both categories. Amazon ECR enhanced scanning is backed by Amazon Inspector and reports on a broader set of vulnerabilities with continuous rescanning, which is what makes it suitable for this gate. An EventBridge rule invokes a Lambda function when the image scan completes; the function reads the Amazon Inspector scan status and reports an Approved or Rejected verdict back to the pipeline, so a Rejected status stops the deployment.

Using Amazon ECR basic scanning (A) — tgv noted that basic scanning uses CVEs from the open-source Clair project while enhanced scanning integrates with Amazon Inspector, so basic scanning does not deliver the required vulnerability coverage for gating a production deployment. Having the Lambda function consume the Clair scan status (E) — Clair is basic scanning's engine, so consuming its status contradicts the use of enhanced scanning; the function must consume the Amazon Inspector scan status. Configuring ECR itself to submit a Rejected status to the pipeline (C) — ECR has no facility to report a verdict into a CodePipeline run, so the pipeline gate has to be driven by a separate component reacting to the scan completion event.

Community Discussion (3 comments)

jamesf 👍 2 Selected: BD
B. Use Amazon ECR Enhanced Scanning - Comprehensive Vulnerability Checks: Amazon ECR enhanced scanning is integrated with Amazon Inspector, providing thorough security checks on container images. It scans for both operating system vulnerabilities and application-level vulnerabilities in programming language packages, which basic scanning does not support. - Integration with Amazon Inspector: Enhanced scanning leverages Amazon Inspector for deeper vulnerability analysis, ensuring the images are secure before deployment. - CRITICAL and HIGH Severity Detection: The enhanced scanning option specifically identifies CRITICAL and HIGH vulnerabilities, aligning with the requirement to only deploy images that do not have these issues.
d0229a2 👍 1
All images pushed to Amazon ECR after enhanced scanning is turned on are continually scanned for the configured duration.
tgv 👍 3 Selected: BD
---> B D As per documentation, basic scanning use CVEs from the open-source Clair project. Enhanced scanning is an integration with Amazon Inspector. This suggests both options use different database/scanners. https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning-enhanced.html https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning-basic.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement has two parts that must be satisfied together. First, the scanning capability must cover both operating system and programming language package vulnerabilities: Amazon ECR enhanced scanning is integrated with Amazon Inspector and provides deeper, continuous vulnerability analysis than basic scanning, whose CVEs come from the open-source Clair project, so enhanced scanning is the correct choice (B). Second, the pipeline must be prevented from deploying images with CRITICAL or HIGH findings: an Amazon EventBridge rule is created to fire when the image scan completes, and the AWS Lambda function it invokes consumes the Amazon Inspector scan status and submits an Approved or Rejected status back to the CodePipeline, so a Rejected verdict halts the deployment before it reaches production (D). Pairing enhanced scanning with the Inspector status keeps the scanner and the status source consistent. B and D are the correct combination.

Why the Other Options Are Wrong

A uses Amazon ECR basic scanning. As tgv observed, basic scanning draws its vulnerability data from the open-source Clair project, which does not provide the depth of coverage the requirement implies for a production deployment gate, whereas enhanced scanning is the Inspector-backed option. Note that option A pairs basic scanning with no gating mechanism at all, so images with HIGH or CRITICAL findings would not block deployment. C configures Amazon ECR to submit a Rejected status to the CI/CD pipeline when the scan returns CRITICAL or HIGH findings. ECR does not provide a facility to report a verdict into a CodePipeline execution; the gating decision must be made by a component reacting to the scan completion event, which is what the EventBridge rule and Lambda function in option D do. E creates an EventBridge rule and Lambda function but has the function consume the Clair scan status. Clair is the engine behind basic scanning, so consuming that status is inconsistent with the enhanced scanning in the correct answer and would not reflect the Inspector findings that matter. B and D are correct.

Community Comment Notes

Community voted B,D unanimously. jamesf identified the keywords as ECR enhanced scanning, Amazon Inspector, and vulnerabilities, and explained that enhanced scanning is integrated with Inspector to provide thorough security checks. tgv drew the decisive distinction, noting from the documentation that basic scanning uses CVEs from the open-source Clair project while enhanced scanning integrates with Amazon Inspector, which is why D must consume the Inspector status rather than the Clair status. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide