nerdexam
Amazon

DVA-C02 · Question #671

A developer is preparing containers for deployment on Amazon EKS. The developer must scan all containers for operating system (OS) and programming language vulnerabilities. Any identified…

The correct answer is D. Integrate Amazon Inspector with Security Hub. Set up enhanced scanning on the ECR repository. Amazon Inspector provides enhanced scanning of container images in Amazon ECR for OS and programming language vulnerabilities. When integrated with AWS Security Hub, findings from these scans are aggregated and visible as Security Hub findings. This meets the requirement to…

Submitted by kevin_r· Mar 5, 2026Security

Question

A developer is preparing containers for deployment on Amazon EKS. The developer must scan all containers for operating system (OS) and programming language vulnerabilities. Any identified vulnerability must be shown as a finding in AWS Security Hub. The developer has an existing Amazon ECR repository. Which solution will meet these requirements?

Options

  • AIntegrate Amazon Macie with Security Hub. Set up basic scanning for the ECR repository. Push
  • BIntegrate AWS Systems Manager Patch Manager with Security Hub. Push the container images
  • CIntegrate Amazon GuardDuty with Security Hub. Push the container images to Amazon ECR.
  • DIntegrate Amazon Inspector with Security Hub. Set up enhanced scanning on the ECR repository.

How the community answered

(22 responses)
  • B
    5% (1)
  • C
    9% (2)
  • D
    86% (19)

Explanation

Amazon Inspector provides enhanced scanning of container images in Amazon ECR for OS and programming language vulnerabilities. When integrated with AWS Security Hub, findings from these scans are aggregated and visible as Security Hub findings. This meets the requirement to scan containers and report vulnerabilities centrally.

Community Discussion

No community discussion yet for this question.

Full DVA-C02 Practice