AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A DevOps team wants to automatically scan container images stored in Amazon ECR for known software vulnerabilities (CVEs) before they are deployed to production, without manually running third-party scanning tools. Which service provides this capability?
- AAmazon GuardDuty
- BAWS Artifact
- CAWS Config
- DAmazon Inspector
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon Inspector
Amazon Inspector automatically and continuously scans Amazon ECR container images (as well as EC2 instances and Lambda functions) for known software vulnerabilities and unintended network exposure, integrating natively without third-party tools.
Why the other options are wrong
- A. GuardDuty performs threat detection via log analysis, not vulnerability scanning of images.
- B. AWS Artifact provides compliance documentation, not vulnerability scanning capabilities.
- C. AWS Config evaluates resource configuration compliance, not software vulnerability scanning.
Amazon Inspector
An automated vulnerability management service that continuously scans EC2 instances, Lambda functions, and container images for software vulnerabilities and network exposure.
- Automatically scans ECR container images for known CVEs
- Provides risk scores to help prioritize remediation
- Continuously rescans as new vulnerabilities are discovered
Memory trick: Inspector inspects images and instances for hidden vulnerabilities.