The CI pipeline builds container images with CodeBuild and stores them in ECR. The security team needs fast detection and notification of image vulnerabilities with minimal operational overhead. Which combination of actions (choose two) meets this need?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon Inspector enhanced scanning for ECR with continuous scanning and create an SNS topic for notifications., Create an EventBridge rule that triggers on Amazon Inspector findings and set an SNS topic as the rule’s target..
Why this is the answer
The combination of enabling Amazon Inspector enhanced scanning for ECR with continuous scanning and creating an SNS topic for notifications, along with creating an EventBridge rule that triggers on Amazon Inspector findings and sets an SNS topic as the rule’s target, directly addresses the requirement for fast detection and notification of image vulnerabilities with minimal operational overhead. Amazon Inspector enhanced scanning provides comprehensive vulnerability analysis, and continuous scanning ensures new vulnerabilities are identified promptly. SNS is the standard AWS service for notifications. EventBridge allows for automated, rule-based responses to Inspector findings, ensuring immediate action without manual intervention. "AWS Lambda enhanced scanning" is not a valid Inspector scanning type. SES is for email sending, not general notifications. ECR default basic scanning is less comprehensive than enhanced scanning and may not meet security team requirements for thorough detection. Implementing a custom Lambda function for notifications adds unnecessary operational overhead compared to the native integration with EventBridge and SNS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed