An ecommerce company runs its web application on Amazon Elastic Container Service (Amazon ECS). Container images are stored in Amazon Elastic Container Registry (Amazon ECR). The security team needs both continuous and on-push image scanning, must view findings on a centralized dashboard alongside other security findings, and must exclude specific repositories from scanning. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Inspector for ECR image scanning. Configure inclusion filters in Amazon ECR for the repositories to be scanned. Send Amazon Inspector findings to AWS Security Hub..
Why this is the answer
The correct solution leverages Amazon Inspector for ECR image scanning because it provides both continuous and on-push scanning, which is a key requirement. Inspector also integrates with AWS Security Hub, allowing findings to be viewed on a centralized dashboard alongside other security findings. Configuring inclusion filters in Amazon ECR for the repositories to be scanned allows for the exclusion of specific repositories, fulfilling another requirement. Incorrect options: ECR basic scanning only provides on-push scanning, not continuous scanning, and its findings are not as comprehensive as Inspector's. Sending findings to Amazon Inspector from ECR basic scanning is redundant and doesn't provide the advanced features of Inspector's native ECR scanning. Sending Amazon Inspector findings to AWS Config is incorrect; Security Hub is the service designed for centralized security findings aggregation and dashboarding. AWS Config is primarily for configuration compliance and auditing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed