Add an ECR lifecycle policy expiring images with the matching tag after 15 days
A DevOps administrator is configuring a repository to store a company's container images. The administrator needs to configure a lifecycle rule that automatically deletes container images that have a specific tag and that are older than 15 days. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
ECR lifecycle policies natively support both halves of the requirement: selection criteria based on a tag and an expiration condition expressed in days (A). That makes the rule declarative and self-executing, with no additional infrastructure, which is what the most-operational-efficiency requirement points to (A). The other options each select the wrong service for the object being managed: CodeArtifact stores language packages rather than container images, S3 stores objects rather than images with ECR's tag semantics, and EC2 Image Builder builds images rather than expiring them.
The requirement is to automatically delete container images that carry a specific tag once they are older than fifteen days, and the repository holding container images is an Amazon ECR repository. ECR lifecycle policies are built for exactly this, allowing rules that match images by tag pattern, including a specific tag value or untagged images, and that expire them after a stated number of days. Adding such a policy to the repository means the expiry happens automatically without any scheduled job or custom code.
Using AWS CodeArtifact with a repository policy to expire old assets (B) — CodeArtifact is a package repository for libraries and dependencies such as npm, Maven, and PyPI packages, and it has no notion of container images or image tags, so it cannot hold or expire the container images described. Using an S3 bucket with a bucket lifecycle policy to expire objects with the matching tag (C) — an S3 bucket lifecycle rule can expire objects by tag prefix or object tags, but the images live in ECR, and duplicating them into S3 would mean managing copies outside the image registry with no benefit. Using an EC2 Image Builder container recipe with a build component to expire the container (D) — Image Builder creates and distributes images; it has no capability to expire or delete existing images based on tag and age.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is to store container images and automatically delete those carrying a specific tag once they exceed fifteen days of age. Amazon Elastic Container Registry is the repository service for container images, and ECR lifecycle policies are designed precisely for automated image retention management: a policy rule can select images by tag pattern, which includes matching a specific tag value or selecting untagged images, and can set an expiration expressed in days after which the matching images are expired automatically (A). Because the policy is evaluated and enforced by the service itself, no scheduled job, script, or additional infrastructure is required, which satisfies the most-operational-efficiency requirement. Srikantha enumerated exactly these capabilities, matching images by tag including specific values and specifying age conditions. A is the correct answer.Why the Other Options Are Wrong
B creates a repository in AWS CodeArtifact and adds a repository policy to expire old assets with the matching tag after fifteen days. CodeArtifact is a repository for software packages and dependencies such as npm, Maven, NuGet, and PyPI packages; it has no concept of container images, image tags, or image layers, so the objects described cannot be stored or expired there. C creates a bucket in Amazon S3 and adds a bucket lifecycle policy to expire objects with the matching tag. An S3 lifecycle rule can expire objects by prefix or object tags, but the container images are held in ECR as managed image versions, and copying them into S3 to expire them would create unmanaged duplicates outside the registry while providing no benefit. D creates an EC2 Image Builder container recipe and adds a build component to expire the container with the matching tag after fifteen days. EC2 Image Builder is a service for building, distributing, and updating images; it provides no capability to expire or delete existing images based on tag and age, and a build component customizes the build rather than performing retention management. A is correct.Community Comment Notes
Community voted A unanimously. Srikantha explained that ECR supports lifecycle policies that automatically manage container image retention, matching images by tags including specific values or untagged, and specifying age conditions for expiration. matt200 selected A and described the repository plus lifecycle policy approach directly. uncledana noted that the requirement is to automatically manage container images based on a specific tag and age, and that ECR lifecycle policies are specifically designed for that. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →