ECR Pull Through Cache and VPC Endpoints for ECS
A company is running an internal application in an Amazon Elastic Container Service (Amazon ECS) cluster on Amazon EC2. The ECS cluster instances can connect to the public internet. The ECS tasks that run on the cluster instances are configured to use images from both private Amazon Elastic Container Registry (Amazon ECR) repositories and a public ECR registry repository. A new security policy requires the company to remove the ECS cluster's direct access to the internet. The company must remove any NAT gateways and internet gateways from the VPC that hosts the cluster. A DevOps engineer needs to ensure the ECS cluster can still download images from both the public ECR registry and the private ECR repositories. Images from the public ECR registry must remain up-to-date. New versions of the images must be available to the ECS cluster within 24 hours of publication. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose three.)
Community Insight
The common trap is assuming ECR Public repositories can be accessed via VPC Endpoints; they cannot, requiring a pull-through cache rule instead.
This question tests securing Amazon ECS by using ECR pull-through cache rules to proxy public images and Interface VPC endpoints for private repositories, eliminating the need for NAT or Internet Gateways.
Candidates often select options involving Lambda or CodeBuild for caching (Option B) or assume VPC endpoints work for public registries (Option D), leading to higher operational overhead or technical impossibility.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To meet the requirements with the least operational overhead while removing internet access, you must address both private and public image sources differently. For private ECR repositories, creating an Amazon ECR Interface VPC endpoint (Option E) allows secure traffic within the VPC without hitting the public internet. For public ECR registry images, since VPC endpoints do not support public registries, you must use an ECR pull-through cache rule (Option C). This caches public images in a private repository within your account, which can then be accessed via the VPC endpoint. Updating task definitions to point to these cached/private sources ensures the cluster functions correctly.Why the Other Options Are Wrong
Option A involves creating individual CodeBuild projects for each image, which creates significant operational overhead and management complexity compared to a single pull-through cache rule. Option B suggests using Lambda to invoke cache rules, which adds unnecessary complexity and latency; the cache updates automatically on demand or via scheduled tasks if needed, but manual invocation isn't the primary mechanism. Option D is technically incorrect because Amazon ECR Public repositories are global and cannot be accessed via regional VPC endpoints.Community Comment Notes
Community consensus strongly supports options C, E, and F. Comments highlight that VPC endpoints don't support public ECR, necessitating the pull-through cache. One user noted that S3 Gateway endpoints (Option F in their context, though not listed here as a distinct option in the final three-choice constraint logic usually implies the standard set) are also needed for metadata layers, but based on the provided options, C and E are the critical specific steps for ECR access. Another comment emphasized that the pull-through cache ensures images remain up-to-date and accessible within the VPC.Official Reference
Exam Strategy
When securing container registries in a restricted VPC, always check if the registry type (Public vs Private) supports VPC endpoints. If it doesn't (like Public ECR), look for 'pull-through cache' as the alternative solution.
Frequently Asked Questions
Can I use a VPC Endpoint for Amazon ECR Public repositories?
No, VPC endpoints do not support ECR Public repositories. You must use a pull-through cache rule to cache public images in a private repository.
Why is Option A not the best choice for caching public images?
Option A requires managing a separate CodeBuild project for each image, creating high operational overhead. The pull-through cache rule automates this efficiently.
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →