Build the base image in an EC2 Image Builder container recipe and distribute to ECR in all three Regions weekly

Answer Correct answer: C — build the base image with an EC2 Image Builder container recipe and distribute it to ECR in all three Regions weekly.

A company uses containers for its applications. The company learns that some container images are missing required security configurations. A DevOps engineer needs to implement a solution to create a standard base image. The solution must publish the base image weekly to the us-west-2 Region, us-east-2 Region, and eu-central-1 Region. Which solution will meet these requirements?

  1. Create an EC2 Image Builder pipeline that uses a container recipe to build the image. Configure the pipeline to distribute the image to an Amazon Elastic Container Registry (Amazon ECR) repository in us-west-2. Configure ECR replication from us-west-2 to us-east-2 and from us-east-2 to eu-central-1. Configure the pipeline to run weekly.
  2. Create an AWS CodePipeline pipeline that uses an AWS CodeBuild project to build the image. Use AWS CodeDeploy to publish the image to an Amazon Elastic Container Registry (Amazon ECR) repository in us-west-2. Configure ECR replication from us-west-2 to us-east-2 and from us-east-2 to eu-central-1. Configure the pipeline to run weekly.
  3. Create an EC2 Image Builder pipeline that uses a container recipe to build the image. Configure the pipeline to distribute the image to Amazon Elastic Container Registry (Amazon ECR) repositories in all three Regions. Configure the pipeline to run weekly. Correct Answer
  4. Create an AWS CodePipeline pipeline that uses an AWS CodeBuild project to build the image. Use AWS CodeDeploy to publish the image to Amazon Elastic Container Registry (Amazon ECR) repositories in all three Regions. Configure the pipeline to run weekly.

Community Votes

C
84%
A
16%

84% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EC2 Image Builder is the AWS service designed for building and distributing container images, and its container distribution settings can push to ECR repositories in multiple Regions directly, which is exactly the three-Region requirement (C). Option A builds only into us-west-2 and then chains ECR replication, which adds replication-lag delay and means the eu-central-1 copy depends on the us-east-2 copy arriving first, an unnecessary hop. Options B and D substitute CodeBuild and CodeDeploy, which are general build/deploy tools that do not provide Image Builder's managed multi-Region image distribution.

A standard base image for containers must be built and published weekly to us-west-2, us-east-2, and eu-central-1. EC2 Image Builder is purpose-built for this: a container recipe defines the image build, and its distribution settings can target an Amazon ECR repository in each of the three Regions in a single pipeline, with the pipeline scheduled to run weekly. This removes the need for cross-Region replication chains and keeps the release cadence in one place.

Building into a single Region and chaining ECR cross-Region replication from us-west-2 to us-east-2 and from us-east-2 to eu-central-1 (A) — replication only fires on image push and introduces lag, so the further Region depends on an intermediate copy arriving, whereas Image Builder distributes directly to all three. Using CodePipeline with CodeBuild and CodeDeploy to publish container images (B and D) — heff_bezos noted the confusion between Image Builder and EC2 AMIs, but Image Builder explicitly supports container recipes and container distribution, whereas CodeDeploy's role is application deployment rather than image distribution to ECR.

Community Discussion (8 comments)

jamesf 👍 5 Selected: C
EC2 Image Builder: - This service is designed to automate the creation and distribution of container images. It supports defining container recipes and automating the build process. Direct Distribution: - EC2 Image Builder can be configured to distribute the images directly to multiple ECR repositories across different regions. This aligns with the requirement of publishing the base image to the us-west-2, us-east-2, and eu-central-1 regions. Weekly Schedule: - EC2 Image Builder can be scheduled to run on a weekly basis, meeting the requirement for regular updates.
noisonnoiton 👍 5 Selected: C
https://docs.aws.amazon.com/ko_kr/imagebuilder/latest/userguide/manage-distribution-settings.html
sinanci 👍 1 Selected: A
A is correct. It offers a more operationally efficient and AWS-native solution for distributing container images across multiple regions.
heff_bezos 👍 1 Selected: D
EC2 Image Builder is for AMIs not container images that go to ECR... "A replication action only occurs once per image push. For example, if you configured cross-Region replication from us-west-2 to us-east-1 and from us-east-1 to us-east-2, an image pushed to us-west-2 replicates to only us-east-1, it doesn't replicate again to us-east-2. This behavior applies to both cross-Region and cross-account replication." https://docs.aws.amazon.com/AmazonECR/latest/userguide/replication.html
tgv 👍 4
---> C You can distributes container image to Amazon ECR repository in multiple regions. --- https://docs.aws.amazon.com/imagebuilder/latest/userguide/cr-upd-container-distribution-settings.html
siheom 👍 1 Selected: A
VOTE A
inturist 👍 2
A replication action only occurs once per image push. For example, if you configured cross-Region replication from us-west-2 to us-east-1 and from us-east-1 to us-east-2, an image pushed to us-west-2 replicates to only us-east-1, it doesn't replicate again to us-east-2. This behavior applies to both cross-Region and cross-account replication.
getadroit 👍 1
B https://aws.amazon.com/blogs/containers/cross-region-replication-in-amazon-ecr-has-landed/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

EC2 Image Builder automates the creation and distribution of machine and container images. Defining the base image as a container recipe and configuring its distribution settings to publish to Amazon ECR repositories in us-west-2, us-east-2, and eu-central-1 means a single pipeline pushes the image directly to all three Regions, and scheduling the pipeline weekly satisfies the release cadence. This is the native, lowest-complexity way to build and fan out a container image to a fixed set of Regions.

Why the Other Options Are Wrong

A configures the pipeline to distribute only to us-west-2 and then chains ECR replication to us-east-2 and from us-east-2 to eu-central-1. Replication triggers on image push and adds lag, so the eu-central-1 copy depends on the us-east-2 copy first existing; distributing directly from the pipeline is simpler and faster. B and D use AWS CodePipeline with CodeBuild and CodeDeploy. CodeBuild can build an image, but CodeDeploy is oriented at deploying applications rather than distributing container images across Regions, and neither provides Image Builder's managed multi-Region container distribution settings. C is the correct answer.

Community Comment Notes

Community voted C (77), with A a 15 percent minority. Commenters linked the EC2 Image Builder documentation for updating container distribution settings and emphasized that Image Builder is specifically designed to distribute container images to ECR repositories in multiple Regions. sinanci defended A as more operationally efficient, but heff_bezos's point that replication adds an unnecessary intermediate hop and that Image Builder does support container images supports choosing C.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide