AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium

A large enterprise has a complex application composed of hundreds of microservices. Each microservice has its own Git repository and CI/CD pipeline using AWS CodePipeline. The security team requires that all container images built by these pipelines undergo automated vulnerability scanning before deployment to Amazon EKS. Where should this scanning be integrated into the CI/CD pipeline to ensure compliance and prevent vulnerable images from reaching production?

  1. AAs a build step, before the image is pushed to Amazon ECR.
  2. BAs a source step, scanning the Dockerfile in the Git repository.
  3. CAs a post-deployment step, after the image is deployed to EKS.
  4. DAs a testing step, after the image is pushed to Amazon ECR but before deployment.
Show answer & explanation

Correct answer: D. As a testing step, after the image is pushed to Amazon ECR but before deployment.

Integrating vulnerability scanning as a testing step after the image is pushed to ECR but before deployment ensures that the final build artifact (the container image) is scanned. This prevents vulnerable images from being deployed to production while using the ECR image as the canonical source for scanning.

Why the other options are wrong

  • A. Scanning before pushing to ECR means the scan is performed on a local artifact, and if the ECR push fails or the image is altered, the scan result might not reflect the deployed image. It's better to scan the final artifact in ECR.
  • B. Scanning only the Dockerfile is insufficient as vulnerabilities can exist in base images, dependencies, or compiled code not visible in the Dockerfile itself.
  • C. Scanning after deployment is too late; a vulnerable image could already be running in production.

Container Image Vulnerability Scanning

The process of analyzing container images for known security vulnerabilities, outdated components, or misconfigurations, typically integrated into CI/CD pipelines.

  • Crucial for preventing vulnerable software from reaching production.
  • Best performed on the final image artifact (e.g., in ECR).
  • Automated tools like Amazon ECR Basic Scanning or third-party scanners are used.

Memory trick: Scan the container 'passport' after it's stamped, before it boards.

More SDLC Automation questions