Continuously scan EKS nodes and ECR images with Amazon Inspector
A company is deploying a new application on AWS. The application consists of an Amazon Elastic Kubernetes Service (Amazon EKS) cluster and an Amazon Elastic Container Registry (Amazon ECR) repository. The EKS cluster has an AWS managed node group. The company's security guidelines state that all resources on AWS must be continuously scanned for security vulnerabilities. Which solution will meet this requirement with the LEAST operational overhead?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Amazon Inspector is the AWS-native vulnerability scanning service that covers both Amazon EC2 instances, which includes managed node group instances, and container images stored in ECR, using a single managed agent rather than self-hosted tooling.
Security guidelines require every AWS resource to be continuously scanned for vulnerabilities, and the environment is an EKS cluster with a managed node group plus an ECR repository. The scanner must run continuously with the least operational overhead.
Expecting AWS Security Hub to perform the scanning. Security Hub aggregates findings from other services such as Inspector, Config, and Macie, and the controls it applies are ultimately Config rules, so it is a findings dashboard rather than the scanner that satisfies the continuous scanning requirement.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Inspector continuously scans for vulnerabilities and unintended network reachability, covering both EC2 instances such as EKS managed node group nodes and container images in ECR. Because the scanning agent and the coverage are managed by AWS, enabling Inspector satisfies the always-on requirement with the least operational overhead and no infrastructure to run.Why the Other Options Are Wrong
A: AWS Security Hub aggregates security findings from partner and AWS services, and it is not the component that performs continuous vulnerability scanning of EKS nodes and ECR images, so enabling it alone does not meet the requirement. C: A self-hosted scanner on a new EC2 instance adds an instance to manage and patch, and ECR basic scan on push only checks images at push time rather than continuously. D: The CloudWatch agent collects metrics and logs and performs no vulnerability scanning, so it cannot satisfy the requirement.Community Comment Notes
The community voted 90 to 1 for B. The single dissenting comment argued for Security Hub, and the majority response clarified that Security Hub is a finding aggregator fed by services such as Inspector, Config, and Macie, which is why Inspector is the scanning component.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →