SCS-C02 exam dumps

SCS-C02 practice question 248 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 248

Single answer

An organization is using Amazon Elastic Container Service (ECS) to manage its containerized workloads. They want to ensure that container images stored in Amazon Elastic Container Registry (Amazon ECR) are free from known vulnerabilities before deployment. Which service or feature should they use to achieve this?

  1. A

    Amazon Inspector

  2. B

    Amazon GuardDuty

  3. C

    Amazon ECR image scanning

  4. D

    AWS Trusted Advisor

Show answer and explanation

Correct answer: C

Explanation

To ensure that container images stored in Amazon ECR are free of vulnerabilities before deployment, the organization should use Amazon ECR image scanning. This feature integrates with vulnerability databases to identify known vulnerabilities in container images, providing a proactive approach to securing workloads. Other services like Amazon Inspector and GuardDuty are useful for broader security tasks but are not specific to pre-deployment image scanning in Amazon ECR.

  • A. Incorrect.

    Amazon Inspector is primarily used for automated security assessments of EC2 instances and container workloads running on Amazon ECS. While it can scan for vulnerabilities, it does not directly scan ECR images for vulnerabilities before deployment.

  • B. Incorrect.

    Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It does not perform vulnerability scanning for container images.

  • C. Correct.

    Amazon ECR image scanning is a feature specifically designed to scan container images stored in Amazon ECR for known vulnerabilities. This is the correct service for ensuring image security before deployment.

  • D. Incorrect.

    AWS Trusted Advisor provides recommendations to optimize AWS environments concerning cost, performance, and security but does not perform vulnerability scans on container images.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam