Scan Lambda packages with Inspector and exclude untagged functions from code scanning
A company has several AWS Lambda functions written in Python. The functions are deployed with the .zip package deployment type. The functions use a Lambda layer that contains common libraries and packages in a .zip file. The Lambda .zip packages and Lambda layer .zip file are stored in an Amazon S3 bucket. The company must implement automatic scanning of the Lambda functions and the Lambda layer to identify CVEs. A subset of the Lambda functions must receive automated code scans to detect potential data leaks and other vulnerabilities. The code scans must occur only for selected Lambda functions, not all the Lambda functions. Which combination of actions will meet these requirements? (Choose three.)
Community Votes
100% of anonymous learners picked answer ABE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Inspector treats Lambda standard scanning and Lambda code scanning as separate switches, and the exclusion mechanism is a tag on the functions to be skipped, so scanning the layer and all functions while scanning code for only the untagged subset requires both switches plus the exclusion tag.
A company has Python Lambda functions deployed as .zip packages with a shared Lambda layer also in .zip, both stored in S3. It must automatically scan the functions and the layer for CVEs, and a subset of the functions must additionally receive code scans for data leaks and other vulnerabilities, with the code scans applied only to that subset.
Enabling scanning in the Monitor settings of only the functions that need code scans. That approach does not give the automatic CVE scanning of the functions and the layer that the requirement asks for across the whole estate, and it leaves the scanning scope configured per function rather than managed centrally with an exclusion tag.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Inspector is the service that performs both kinds of scanning here, so activating it and starting automated CVE scans covers the functions and the Lambda layer for dependency vulnerabilities, which is why A is correct. CVE coverage for all functions plus code scanning for only a subset requires enabling Lambda standard scanning and Lambda code scanning as distinct settings, which is why B is correct. The subset requirement is then expressed as an exclusion rather than an inclusion, because the tag key InspectorCodeExclusion with the value LambdaCodeScanning is applied to the functions that must not receive code scans, leaving the untagged remainder in scope. That is why E is correct and it is the mechanism that keeps the scan selection declarative rather than a per-function setting the team has to remember to toggle.Why the Other Options Are Wrong
C: GuardDuty is a threat detection service that analyses account and network activity, and its Lambda Protection feature looks for suspicious API activity such as cryptocurrency mining, not for CVEs in packaged dependencies or code vulnerabilities in a function's own source, so it does not satisfy either scanning requirement. D: Enabling scanning in the Monitor settings of individual functions covers code scanning for those functions only and provides no mechanism to scan the shared Lambda layer for CVEs across the estate, so the automatic scanning of all functions and the layer is not delivered.Community Comment Notes
The community voted 100 to 0 for A, B, and E, and the top-voted comment mapped each choice to its requirement, Inspector for Lambda standard scanning and code scanning, and a tag to keep the code scan conditional rather than applying it to every function. Another commenter explained the division of labour, that CVE detection needs Lambda standard scanning while data leak detection needs Lambda code scanning, and that the tag provides the conditional exclusion. A further commenter linked the Inspector Lambda scanning documentation, which documents the InspectorCodeExclusion tag.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →