A company uses AWS Lambda functions and has enabled Amazon Inspector with Lambda standard scanning and Lambda code scanning. In the Amazon Inspector console, some functions are not being scanned with the reason “scan eligibility expired.” What should the security engineer check to determine why these scans are failing?
Choose an answer
Tap an option to check your answer.
Correct answer: Determine whether the unscanned Lambda functions have been invoked within the last 90 days..
Why this is the answer
Amazon Inspector Lambda standard scanning and code scanning only apply to Lambda functions that have been invoked within the last 90 days. If a function has not been invoked during this period, its scan eligibility expires, and Inspector will not scan it. Therefore, checking the invocation history of the unscanned functions is the correct first step. The AmazonInspector2ServiceRolePolicy is a managed policy that grants necessary permissions for Inspector to operate, but it's unlikely to be the cause of "scan eligibility expired" if other functions are scanning successfully. Increasing the Lambda function timeout is irrelevant to scan eligibility. Creating a custom runtime with an Inspector agent is not how Inspector scans Lambda functions; Inspector integrates directly with Lambda for scanning.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed