A company uses AWS CodeArtifact repositories with public upstreams. Developers pull open-source packages from the internal repos. A critical vulnerability is found in the latest version of a package; the security team has produced a patched build and must prevent the vulnerable version from being downloaded while still allowing the security team to publish the patched version. Which actions satisfy both requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Update the affected CodeArtifact package version status to archived., Change the CodeArtifact package origin control settings to allow direct publishing and to block upstream operations..
Why this is the answer
Archiving a package version prevents it from being pulled by package managers while still allowing it to be viewed and managed within CodeArtifact. This satisfies the requirement to prevent developers from downloading the vulnerable version. Changing the package origin control settings to "allow direct publishing" enables the security team to publish their patched version directly to the repository. Setting "block upstream operations" prevents CodeArtifact from pulling the vulnerable version from public upstreams, ensuring it's not re-introduced. Setting the status to "deleted" would permanently remove the package, which isn't ideal if the security team needs to reference it or publish a patched version. "Unlisted" would hide it but might not fully prevent downloads depending on the package manager. Blocking direct publishing would prevent the security team from publishing their patched version.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed