AWS Certified DevOps Engineer – ProfessionalSDLC AutomationEasy
A security team requires that all container images deployed to Amazon Elastic Kubernetes Service (EKS) clusters must be scanned for vulnerabilities before deployment. If vulnerabilities are found, the deployment should be blocked, and the development team notified. Which AWS service should be integrated into the CI/CD pipeline to meet this requirement efficiently?
- AAWS Security Hub
- BAWS WAF
- CAmazon GuardDuty
- DAmazon Inspector
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon Inspector
Amazon Inspector is a vulnerability management service that automatically discovers and scans AWS workloads for vulnerabilities. It can scan container images stored in Amazon ECR for software vulnerabilities, making it ideal for integration into a CI/CD pipeline to block deployments based on scan results.
Why the other options are wrong
- A. AWS Security Hub provides a comprehensive view of security alerts and compliance status across AWS accounts, but it aggregates findings from other services like Inspector, rather than performing the direct scanning itself.
- B. AWS WAF (Web Application Firewall) protects web applications from common web exploits, not for scanning container images for vulnerabilities.
- C. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for scanning container images for vulnerabilities during CI/CD.
Container Image Vulnerability Scanning
The process of automatically scanning container images for known software vulnerabilities before deployment, often integrated into a CI/CD pipeline.
- Essential for secure software supply chain.
- Identifies CVEs (Common Vulnerabilities and Exposures).
- Can block deployments based on severity thresholds.
- Amazon Inspector is a key AWS service for this.
Memory trick: Inspect containers for vulnerabilities to prevent bad deployments.