Turn on ECR enhanced scanning and invoke an EC2 Image Builder container image pipeline from an Inspector finding event
A company runs its container workloads in AWS App Runner. A DevOps engineer manages the company's container repository in Amazon Elastic Container Registry (Amazon ECR). The DevOps engineer must implement a solution that continuously monitors the container repository. The solution must create a new container image when the solution detects an operating system vulnerability or language package vulnerability. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The vulnerability signal must come from ECR enhanced scanning, which is the Inspector-backed option covering both operating system and language package vulnerabilities (A). The remediation mechanism must be an image pipeline, because the requirement is to create a new container image, which is what EC2 Image Builder's container image pipeline provides (A). Option C's basic scanning reports on push rather than continuously, and its CodeBuild project would rebuild from source rather than from a detected finding. Option D uses Systems Manager Compliance, which assesses managed node configuration rather than container image vulnerabilities, and Option B uses GuardDuty Malware Protection, which targets malicious files rather than vulnerability findings.
Continuously monitoring the container repository and automatically producing a new image when an operating system or language package vulnerability appears requires both a vulnerability source and a rebuild mechanism. Amazon ECR enhanced scanning is backed by Amazon Inspector and reports both categories of vulnerability, and an EventBridge rule on the Inspector finding event invokes an EC2 Image Builder container image pipeline that rebuilds and pushes a new image to the ECR repository, closing the loop without manual intervention.
Turning on basic scanning and reacting to an ECR image action event (C) — jamesf and trungtd both identify enhanced scanning as the requirement, since basic scanning does not provide the continuous Inspector-backed coverage of both operating system and language package vulnerabilities, and an image action event fires on push rather than on a vulnerability finding. Using Amazon GuardDuty Malware Protection on the container workload (B) — Malware Protection detects malicious files in workloads, not operating system or language package vulnerabilities in images, so the resulting findings are not the ones that must trigger a rebuild. Configuring Systems Manager Compliance to scan managed nodes (D) — that evaluates configuration compliance of managed nodes, not container image contents.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The solution needs a vulnerability detection source and a remediation mechanism, and the requirement specifies both operating system and language package vulnerabilities in a container repository, monitored continuously. Amazon ECR enhanced scanning is integrated with Amazon Inspector and performs deep, continuous vulnerability scanning of images covering both categories, so it is turned on for the repository. An Amazon EventBridge rule is then created to capture the Inspector finding event and uses it to invoke an EC2 Image Builder container image pipeline, which rebuilds the image and re-uploads the container to the repository. Because the trigger is the finding event rather than a push, the repository is monitored continuously and a new image is produced automatically when a vulnerability appears (A). A is the correct answer.Why the Other Options Are Wrong
B uses an EC2 Image Builder container image pipeline, which is the correct remediation mechanism, but enables Amazon GuardDuty Malware Protection on the container workload and triggers on a GuardDuty finding event. Malware Protection detects malicious files in a workload, which is a different class of detection from the operating system and programming language package vulnerabilities the requirement names, so the findings that would trigger rebuilds would not be the required ones. C creates an AWS CodeBuild project, turns on basic scanning, and triggers on an ECR image action event. Basic scanning does not provide the continuous Inspector-backed coverage required, and an image action event fires when an image is pushed rather than when a vulnerability is detected, so a newly discovered vulnerability in an already-stored image would never trigger a rebuild. D creates a CodeBuild project and configures AWS Systems Manager Compliance to scan all managed nodes, triggering on a configuration compliance state change event. Systems Manager Compliance evaluates the configuration posture of managed nodes; it does not scan container images for package vulnerabilities, so its findings are unrelated to the requirement. A is correct.Community Comment Notes
Community voted A unanimously. TEC1 identified turning on enhanced scanning in the ECR repository settings as the enabling step, noting that this enables Amazon Inspector to scan images for vulnerabilities. jamesf named the keywords as enhanced scanning, Amazon ECR, Amazon Inspector, and vulnerabilities. trungtd explained that enhanced scanning provides deep and comprehensive vulnerability scanning for container images using Amazon Inspector, which is what makes option A the only choice with both the correct detection source and a rebuild mechanism. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →