Use Amazon Inspector for ECR/ECS vulnerability scanning aggregated to a central Security Hub

Answer Correct answer: A — Amazon Inspector scans ECS/ECR for OS and library vulnerabilities and forwards findings to a central Security Hub for the audit team.

A company uses Amazon Elastic Container Service (Amazon ECS) containers that have the Fargate launch type. The containers run web and mobile applications that are written in Java and Node.js. To meet network segmentation requirements, each of the company’s business units deploys applications in its own dedicated AWS account. Each business unit stores container images in an Amazon Elastic Container Registry (Amazon ECR) private registry in its own account. A security engineer must recommend a solution to scan ECS containers and ECR registries for vulnerabilities in operating systems and programming language libraries. The company’s audit team must be able to identify potential vulnerabilities that exist in any of the accounts where applications are deployed. Which solution will meet these requirements?

  1. In each account, update the ECR registry to use Amazon Inspector instead of the default scanning service. Configure Amazon Inspector to forward vulnerability findings to AWS Security Hub in a central security account. Provide access for the audit team to use Security Hub to review the findings. Correct Answer
  2. In each account, configure AWS Config to monitor the configuration of the ECS containers and the ECR registry. Configure AWS Config conformance packs for vulnerability scanning. Create an AWS Config aggregator in a central account to collect configuration and compliance details from all accounts. Provide the audit team with access to AWS Config in the account where the aggregator is configured.
  3. In each account, configure AWS Audit Manager to scan the ECS containers and the ECR registry. Configure Audit Manager to forward vulnerability findings to AWS Security Hub in a central security account. Provide access for the audit team to use Security Hub to review the findings.
  4. In each account, configure Amazon GuardDuty to scan the ECS containers and the ECR registry. Configure GuardDuty to forward vulnerability findings to AWS Security Hub in a central security account. Provide access for the audit team to use Security Hub to review the findings.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Amazon Inspector is the AWS service purpose-built for vulnerability scanning of operating systems and software packages (including container images in ECR and Lambda). Forwarding its findings to a central Security Hub, where the audit team already has access, satisfies both the scanning and cross-account visibility requirements.

A company runs Fargate ECS workloads and stores images in per-account ECR private registries. The audit team needs to identify OS and language-library vulnerabilities across all accounts. Amazon Inspector performs CVE scanning of container images in ECR and running ECS tasks, and can forward findings to AWS Security Hub in a central security account for consolidated review.

Picking AWS Config, Audit Manager, or GuardDuty. AWS Config evaluates configuration/compliance posture but does not scan images for CVEs; Audit Manager assesses control evidence; GuardDuty is threat detection for active malicious behavior, not package vulnerability scanning.

Community Discussion (9 comments)

phmeeeee 👍 1 Selected: A
Amazon Inspector is for vulnerability scanning including ECR and Security Hub is for centrailize of the security finding.
navid1365 👍 2 Selected: A
A is correct. Out of all the options only Amazon Inspector can perform CVE scanning.
aescudero51 👍 2 Selected: A
My answer is A https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html
5409b91 👍 2 Selected: A
Amazon Inspector: Amazon Inspector is a tool specifically designed to scan containers and registries for vulnerabilities in operating systems and programming language libraries. Integration with AWS Security Hub: Configuring Amazon Inspector to send vulnerability findings to AWS Security Hub in a central security account allows for centralized visibility and facilitates access for the audit team to review the findings. Account configuration: Updating each ECR registry in each account to use Amazon Inspector ensures that all registries and containers are properly scanned in each business account.
Certified101 👍 2 Selected: A
A NOT Guarduty you need inspector
Nash101 👍 1
A Amazon Inspector is specifically designed for scanning container images in ECR for vulnerabilities in operating systems and libraries. It effectively addresses the need to scan both containers and container images.
anandkl80 👍 1
A • Amazon Inspector: It is a security assessment service that helps improve the security and compliance of applications by scanning them for vulnerabilities or deviations from best practices, including scans of the operating system and application libraries within container images stored in ECR. • Integration with Security Hub: Inspector can integrate with AWS Security Hub, which provides a comprehensive view of security alerts and security posture across AWS accounts. By forwarding findings to Security Hub in a central account, the company ensures that the audit team can access and review these findings across all business units from a single pane.
Zek 👍 1
A Amazon Inspector automatically discovers and scans running Amazon EC2 instances, container images in Amazon Elastic Container Registry (Amazon ECR), and AWS Lambda functions for known software vulnerabilities and unintended network exposure. https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html
danish1234 👍 1 Selected: D
D is the answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Inspector automatically discovers and scans container images in Amazon ECR and running ECS tasks for known software vulnerabilities in the OS and application libraries, which is exactly the requirement. By configuring Inspector in each account to send findings to AWS Security Hub in a central security account, the audit team gets a single pane to review vulnerabilities across every business-unit account, meeting the central visibility need.

Why the Other Options Are Wrong

B is wrong because AWS Config conformance packs evaluate configuration compliance, not OS/library CVEs in images. C is wrong because AWS Audit Manager collects control-evidence for audits; it does not scan containers or registries for vulnerabilities. D is wrong because GuardDuty detects active threats and malicious activity, not static package vulnerabilities in container images or registries.

Community Comment Notes

The community overwhelmingly selected A, noting "only Amazon Inspector can perform CVE scanning." A commenter linked the ECR image-scanning docs and the Inspector overview confirming ECR and ECS coverage. One stray D vote was not supported.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide