Scan Lambda packages with Inspector and exclude untagged functions from code scanning

Answer Correct answers: A, B, E — Activate Inspector, enable Lambda standard and code scanning, and tag the excluded functions with InspectorCodeExclusion.

A company has several AWS Lambda functions written in Python. The functions are deployed with the .zip package deployment type. The functions use a Lambda layer that contains common libraries and packages in a .zip file. The Lambda .zip packages and Lambda layer .zip file are stored in an Amazon S3 bucket. The company must implement automatic scanning of the Lambda functions and the Lambda layer to identify CVEs. A subset of the Lambda functions must receive automated code scans to detect potential data leaks and other vulnerabilities. The code scans must occur only for selected Lambda functions, not all the Lambda functions. Which combination of actions will meet these requirements? (Choose three.)

  1. Activate Amazon Inspector. Start automated CVE scans. Correct Answer
  2. Activate Lambda standard scanning and Lambda code scanning in Amazon Inspector. Correct Answer
  3. Enable Amazon GuardDuty. Enable the Lambda Protection feature in GuardDuty.
  4. Enable scanning in the Monitor settings of the Lambda functions that need code scans.
  5. Tag Lambda functions that do not need code scans. In the tag, include a key of InspectorCodeExclusion and a value of LambdaCodeScanning. Correct Answer

Community Votes

ABE
100%

100% of anonymous learners picked answer ABE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Inspector treats Lambda standard scanning and Lambda code scanning as separate switches, and the exclusion mechanism is a tag on the functions to be skipped, so scanning the layer and all functions while scanning code for only the untagged subset requires both switches plus the exclusion tag.

A company has Python Lambda functions deployed as .zip packages with a shared Lambda layer also in .zip, both stored in S3. It must automatically scan the functions and the layer for CVEs, and a subset of the functions must additionally receive code scans for data leaks and other vulnerabilities, with the code scans applied only to that subset.

Enabling scanning in the Monitor settings of only the functions that need code scans. That approach does not give the automatic CVE scanning of the functions and the layer that the requirement asks for across the whole estate, and it leaves the scanning scope configured per function rather than managed centrally with an exclusion tag.

Community Discussion (4 comments)

vip2 👍 5 Selected: ABE
A, B and E Inspector for Lamda std scanning and code scanning Lambda Function with monitor setting to code scan Tag for conditional function, not for all functions
JoeTromundo 👍 2 Selected: ABE
A: Amazon Inspector can automatically scan your Lambda functions for known vulnerabilities (CVEs) in the dependencies of the functions. This action will initiate the security scanning of Lambda functions and Lambda layers to detect vulnerabilities. B: Amazon Inspector provides enhanced scanning features for Lambda functions. This includes both standard scanning (for CVEs in dependencies and layers) and code scanning (for potential vulnerabilities, like data leaks, directly in the code). E: https://docs.aws.amazon.com/lambda/latest/dg/governance-code-scanning.html#:~:text=To%20exclude%20a%20Lambda%20function,Value%3ALambdaStandardScanning. "To exclude a Lambda function from code scans, tag the function with the following key-value pair: Key:InspectorCodeExclusion Value:LambdaCodeScanning"
kgpoj 👍 2 Selected: ABE
A: Need to Activate Amazon Inspector first B: For CVE, need to use Lambda standard scanning B: For data leaks, need to use Lambda code scanning E: Tag Lambda functions that do not need code scans
guruguru 👍 1
ABE, https://docs.aws.amazon.com/inspector/latest/user/scanning-lambda.html To exclude a Lambda function from Lambda standard scanning, tag the function with the following key-value pair: Key:InspectorExclusion Value:LambdaStandardScanning

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Inspector is the service that performs both kinds of scanning here, so activating it and starting automated CVE scans covers the functions and the Lambda layer for dependency vulnerabilities, which is why A is correct. CVE coverage for all functions plus code scanning for only a subset requires enabling Lambda standard scanning and Lambda code scanning as distinct settings, which is why B is correct. The subset requirement is then expressed as an exclusion rather than an inclusion, because the tag key InspectorCodeExclusion with the value LambdaCodeScanning is applied to the functions that must not receive code scans, leaving the untagged remainder in scope. That is why E is correct and it is the mechanism that keeps the scan selection declarative rather than a per-function setting the team has to remember to toggle.

Why the Other Options Are Wrong

C: GuardDuty is a threat detection service that analyses account and network activity, and its Lambda Protection feature looks for suspicious API activity such as cryptocurrency mining, not for CVEs in packaged dependencies or code vulnerabilities in a function's own source, so it does not satisfy either scanning requirement. D: Enabling scanning in the Monitor settings of individual functions covers code scanning for those functions only and provides no mechanism to scan the shared Lambda layer for CVEs across the estate, so the automatic scanning of all functions and the layer is not delivered.

Community Comment Notes

The community voted 100 to 0 for A, B, and E, and the top-voted comment mapped each choice to its requirement, Inspector for Lambda standard scanning and code scanning, and a tag to keep the code scan conditional rather than applying it to every function. Another commenter explained the division of labour, that CVE detection needs Lambda standard scanning while data leak detection needs Lambda code scanning, and that the tag provides the conditional exclusion. A further commenter linked the Inspector Lambda scanning documentation, which documents the InspectorCodeExclusion tag.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide