Turn on ECR enhanced scanning and invoke an EC2 Image Builder container image pipeline from an Inspector finding event

Answer Correct answer: A — enable ECR enhanced scanning and invoke an EC2 Image Builder container image pipeline from an Inspector finding event.

A company runs its container workloads in AWS App Runner. A DevOps engineer manages the company's container repository in Amazon Elastic Container Registry (Amazon ECR). The DevOps engineer must implement a solution that continuously monitors the container repository. The solution must create a new container image when the solution detects an operating system vulnerability or language package vulnerability. Which solution will meet these requirements?

  1. Use EC2 Image Builder to create a container image pipeline. Use Amazon ECR as the target repository. Turn on enhanced scanning on the ECR repository. Create an Amazon EventBridge rule to capture an Inspector? finding event. Use the event to invoke the image pipeline. Re-upload the container to the repository. Correct Answer
  2. Use EC2 Image Builder to create a container image pipeline. Use Amazon ECR as the target repository. Enable Amazon GuardDuty Malware Protection on the container workload. Create an Amazon EventBridge rule to capture a GuardDuty finding event. Use the event to invoke the image pipeline.
  3. Create an AWS CodeBuild project to create a container image. Use Amazon ECR as the target repository. Turn on basic scanning on the repository. Create an Amazon EventBridge rule to capture an ECR image action event. Use the event to invoke the CodeBuild project. Re-upload the container to the repository.
  4. Create an AWS CodeBuild project to create a container image. Use Amazon ECR as the target repository. Configure AWS Systems Manager Compliance to scan all managed nodes. Create an Amazon EventBridge rule to capture a configuration compliance state change event. Use the event to invoke the CodeBuild project.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The vulnerability signal must come from ECR enhanced scanning, which is the Inspector-backed option covering both operating system and language package vulnerabilities (A). The remediation mechanism must be an image pipeline, because the requirement is to create a new container image, which is what EC2 Image Builder's container image pipeline provides (A). Option C's basic scanning reports on push rather than continuously, and its CodeBuild project would rebuild from source rather than from a detected finding. Option D uses Systems Manager Compliance, which assesses managed node configuration rather than container image vulnerabilities, and Option B uses GuardDuty Malware Protection, which targets malicious files rather than vulnerability findings.

Continuously monitoring the container repository and automatically producing a new image when an operating system or language package vulnerability appears requires both a vulnerability source and a rebuild mechanism. Amazon ECR enhanced scanning is backed by Amazon Inspector and reports both categories of vulnerability, and an EventBridge rule on the Inspector finding event invokes an EC2 Image Builder container image pipeline that rebuilds and pushes a new image to the ECR repository, closing the loop without manual intervention.

Turning on basic scanning and reacting to an ECR image action event (C) — jamesf and trungtd both identify enhanced scanning as the requirement, since basic scanning does not provide the continuous Inspector-backed coverage of both operating system and language package vulnerabilities, and an image action event fires on push rather than on a vulnerability finding. Using Amazon GuardDuty Malware Protection on the container workload (B) — Malware Protection detects malicious files in workloads, not operating system or language package vulnerabilities in images, so the resulting findings are not the ones that must trigger a rebuild. Configuring Systems Manager Compliance to scan managed nodes (D) — that evaluates configuration compliance of managed nodes, not container image contents.

Community Discussion (4 comments)

TEC1 👍 5 Selected: A
Turn on enhanced scanning in the Amazon ECR repository settings. This enables Amazon Inspector to scan images for vulnerabilities.
jamesf 👍 4 Selected: A
Keywords: Enhanced scanning, Amazon ECR, Amazon Inspector, vulnerabilities
tgv 👍 4 Selected: A
---> A
trungtd 👍 4 Selected: A
Enhanced scanning provides deep and comprehensive scanning for vulnerabilities in container images using Amazon Inspector.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The solution needs a vulnerability detection source and a remediation mechanism, and the requirement specifies both operating system and language package vulnerabilities in a container repository, monitored continuously. Amazon ECR enhanced scanning is integrated with Amazon Inspector and performs deep, continuous vulnerability scanning of images covering both categories, so it is turned on for the repository. An Amazon EventBridge rule is then created to capture the Inspector finding event and uses it to invoke an EC2 Image Builder container image pipeline, which rebuilds the image and re-uploads the container to the repository. Because the trigger is the finding event rather than a push, the repository is monitored continuously and a new image is produced automatically when a vulnerability appears (A). A is the correct answer.

Why the Other Options Are Wrong

B uses an EC2 Image Builder container image pipeline, which is the correct remediation mechanism, but enables Amazon GuardDuty Malware Protection on the container workload and triggers on a GuardDuty finding event. Malware Protection detects malicious files in a workload, which is a different class of detection from the operating system and programming language package vulnerabilities the requirement names, so the findings that would trigger rebuilds would not be the required ones. C creates an AWS CodeBuild project, turns on basic scanning, and triggers on an ECR image action event. Basic scanning does not provide the continuous Inspector-backed coverage required, and an image action event fires when an image is pushed rather than when a vulnerability is detected, so a newly discovered vulnerability in an already-stored image would never trigger a rebuild. D creates a CodeBuild project and configures AWS Systems Manager Compliance to scan all managed nodes, triggering on a configuration compliance state change event. Systems Manager Compliance evaluates the configuration posture of managed nodes; it does not scan container images for package vulnerabilities, so its findings are unrelated to the requirement. A is correct.

Community Comment Notes

Community voted A unanimously. TEC1 identified turning on enhanced scanning in the ECR repository settings as the enabling step, noting that this enables Amazon Inspector to scan images for vulnerabilities. jamesf named the keywords as enhanced scanning, Amazon ECR, Amazon Inspector, and vulnerabilities. trungtd explained that enhanced scanning provides deep and comprehensive vulnerability scanning for container images using Amazon Inspector, which is what makes option A the only choice with both the correct detection source and a rebuild mechanism. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide