Continuously scan EKS nodes and ECR images with Amazon Inspector

Answer Correct answer: B — Activate Amazon Inspector to continuously scan the EKS managed node group nodes and the ECR repository images.

A company is deploying a new application on AWS. The application consists of an Amazon Elastic Kubernetes Service (Amazon EKS) cluster and an Amazon Elastic Container Registry (Amazon ECR) repository. The EKS cluster has an AWS managed node group. The company's security guidelines state that all resources on AWS must be continuously scanned for security vulnerabilities. Which solution will meet this requirement with the LEAST operational overhead?

  1. Activate AWS Security Hub. Configure Security Hub to scan the EKS nodes and the ECR repository.
  2. Activate Amazon Inspector to scan the EKS nodes and the ECR repository. Correct Answer
  3. Launch a new Amazon EC2 instance and install a vulnerability scanning tool from AWS Marketplace. Configure the EC2 instance to scan the EKS nodes. Configure Amazon ECR to perform a basic scan on push.
  4. Install the Amazon CloudWatch agent on the EKS nodes. Configure the CloudWatch agent to scan continuously. Configure Amazon ECR to perform a basic scan on push.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Amazon Inspector is the AWS-native vulnerability scanning service that covers both Amazon EC2 instances, which includes managed node group instances, and container images stored in ECR, using a single managed agent rather than self-hosted tooling.

Security guidelines require every AWS resource to be continuously scanned for vulnerabilities, and the environment is an EKS cluster with a managed node group plus an ECR repository. The scanner must run continuously with the least operational overhead.

Expecting AWS Security Hub to perform the scanning. Security Hub aggregates findings from other services such as Inspector, Config, and Macie, and the controls it applies are ultimately Config rules, so it is a findings dashboard rather than the scanner that satisfies the continuous scanning requirement.

Community Discussion (12 comments)

AzureDP900 👍 1
B is most appropriate and no additional overhead.
9f02c8d 👍 1
A is the correct answer, not B is focused primarily on scanning Amazon EC2 instances for vulnerabilities and does not natively support scanning Amazon EKS nodes or Amazon ECR repositories
iulian0585 👍 3 Selected: B
A. Activate AWS Security Hub: While AWS Security Hub aggregates security findings from various AWS services, it is not primarily designed for continuous scanning of EKS nodes or ECR repositories. Security Hub is more suited for compliance checks and aggregation of security alerts from multiple sources.
blackname 👍 4 Selected: B
A -> False. Security Hub is just a Finding aggregator of other services like AWS config, Inspector, Macie, ..., even security hub controls are in the end config rules. B -> True. Inspector scans EC2, ECR, lambda functions (either layer analysis, either deep scan of the code), ... C -> False. Has a lot of effort. Plus "perform a basic scan on push" is a deprecated thing, inspector should be used. D -> False. CW Agent does not report vulns. Inspector uses SSM Agent to perform vulnerability scans. Plus "perform a basic scan on push" is a deprecated thing, inspector should be used.
Fu7ed 👍 2 Selected: B
Configuration and vulnerability analysis in Amazon EKS - You can use Amazon Inspector to check for unintended network accessibility of your nodes and for vulnerabilities on those Amazon EC2 instances. https://docs.aws.amazon.com/eks/latest/userguide/configuration-vulnerability-analysis.html Amazon Inspector automatically discovers and scans running Amazon EC2 instances, container images in Amazon Elastic Container Registry (Amazon ECR), and AWS Lambda functions for known software vulnerabilities and unintended network exposure. https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html So, answer is B.
4555894 👍 1 Selected: B
EKS nodes == EC2 , ECR repository = AWS Inspector
tushar321 👍 2
B. Inspector
AwsZora 👍 1 Selected: A
Inspector not suppot for eks
teo2157 👍 4 Selected: B
Security hub integrates many Security features but the scaning itself is done by Amazon Inspector so going for B.
Zas1 👍 4 Selected: B
You can use Amazon Inspector to check for unintended network accessibility of your nodes and for vulnerabilities on those Amazon EC2 instances. https://docs.aws.amazon.com/eks/latest/userguide/configuration-vulnerability-analysis.html
Russs99 👍 1 Selected: A
A is the correct answer for the given scenario
devnv 👍 1
A is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Inspector continuously scans for vulnerabilities and unintended network reachability, covering both EC2 instances such as EKS managed node group nodes and container images in ECR. Because the scanning agent and the coverage are managed by AWS, enabling Inspector satisfies the always-on requirement with the least operational overhead and no infrastructure to run.

Why the Other Options Are Wrong

A: AWS Security Hub aggregates security findings from partner and AWS services, and it is not the component that performs continuous vulnerability scanning of EKS nodes and ECR images, so enabling it alone does not meet the requirement. C: A self-hosted scanner on a new EC2 instance adds an instance to manage and patch, and ECR basic scan on push only checks images at push time rather than continuously. D: The CloudWatch agent collects metrics and logs and performs no vulnerability scanning, so it cannot satisfy the requirement.

Community Comment Notes

The community voted 90 to 1 for B. The single dissenting comment argued for Security Hub, and the majority response clarified that Security Hub is a finding aggregator fed by services such as Inspector, Config, and Macie, which is why Inspector is the scanning component.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide