A company runs an Amazon EKS cluster (with an AWS managed node group) and stores container images in Amazon ECR. Security policy requires continuous vulnerability scanning of all AWS resources. Which option meets this requirement with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon Inspector to perform continuous vulnerability scanning of the EKS nodes and Amazon ECR..
Why this is the answer
Amazon Inspector is the correct choice because it provides automated, continuous vulnerability scanning for both Amazon ECR repositories and Amazon EC2 instances, which include the underlying instances of EKS managed node groups. This directly addresses the requirement for continuous scanning of both container images and the compute environment with minimal operational overhead, as Inspector is a fully managed service. AWS Security Hub aggregates security findings but does not perform the actual vulnerability scanning itself; it relies on other services like Inspector. Launching an EC2 instance with a third-party scanner introduces significant operational overhead for installation, configuration, and maintenance. The Amazon CloudWatch agent is primarily for collecting metrics and logs, not for performing vulnerability scans.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed