A company runs internal microservices on Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type and uses Amazon Elastic Container Registry (Amazon ECR) private repositories. A security engineer must encrypt the ECR repositories with AWS Key Management Service (AWS KMS) and scan container images for common vulnerabilities and exposures (CVEs). Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Recreate the ECR repositories with KMS encryption enabled and enable ECR image scanning. Review the scan report after the next image push..
Why this is the answer
To encrypt existing ECR repositories with KMS, you must recreate them because KMS encryption is a setting configured at repository creation. Similarly, ECR image scanning is a repository-level setting that needs to be enabled when the repository is created or updated. After enabling both, pushing a new image will trigger the scan, and the reports will be available. The other options are incorrect: Installing the Amazon Inspector Agent on EC2 instances is for host-level vulnerability scanning, not for scanning container images within ECR. Recreating repositories with KMS encryption and ECR image scanning is correct, but installing AWS Systems Manager Agent and running an inventory report does not perform CVE scanning of container images. AWS Trusted Advisor provides general best practice checks and cost optimization, not detailed CVE scanning of container images or EC2 instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed