nerdexam
AmazonAmazon

DOP-C02 · Question #267

DOP-C02 Question #267: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #267. The question stem and answer options stay visible for context.

Submitted by valeria.br· Mar 6, 2026Security and Compliance

Question

A company needs to increase the security of the container images that run in its production environment. The company wants to integrate operating system scanning and programming language package vulnerability scanning for the containers in its CI/CD pipeline. The CI/CD pipeline is an AWS CodePipeline pipeline that includes an AWS CodeBuild build project, AWS CodeDeploy actions, and an Amazon Elastic Container Registry (Amazon ECR) repository. A DevOps engineer needs to add an image scan to the CI/CD pipeline. The CI/CD pipeline must deploy only images without CRITICAL and HIGH findings into production. Which combination of steps will meet these requirements? (Choose two.)

Options

  • AUse Amazon ECR basic scanning.
  • BUse Amazon ECR enhanced scanning.
  • CConfigure Amazon ECR to submit a Rejected status to the CI/CD pipeline when the image scan
  • DConfigure an Amazon EventBridge rule to invoke an AWS Lambda function when the image scan
  • EConfigure an Amazon EventBridge rule to invoke an AWS Lambda function when the image scan

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Container image scanning#ECR enhanced scanning#CI/CD security#Event-driven security enforcement
Full DOP-C02 PracticeBrowse All DOP-C02 Questions