nerdexam
Amazon

SCS-C02 · Question #12

A company is running internal microservices on Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type. The company is using Amazon Elastic Container Registry (Amazon ECR) privat

The correct answer is B. Recreate the ECR repositories with KMS encryption and ECR scanning enabled. Analyze the. https://docs.aws.amazon.com/AmazonECR/latest/userguide/repository-create.html https://docs.aws.amazon.com/AmazonECR/latest/userguide/repository-edit.html

Submitted by carter_n· Mar 6, 2026Infrastructure Security

Question

A company is running internal microservices on Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type. The company is using Amazon Elastic Container Registry (Amazon ECR) private repositories. A security engineer needs to encrypt the private repositories by using AWS Key Management Service (AWS KMS). The security engineer also needs to analyze the container images for any common vulnerabilities and exposures (CVEs). Which solution will meet these requirements?

Options

  • AEnable KMS encryption on the existing ECR repositories. Install Amazon Inspector Agent from
  • BRecreate the ECR repositories with KMS encryption and ECR scanning enabled. Analyze the
  • CRecreate the ECR repositories with KMS encryption and ECR scanning enabled. Install AWS
  • DEnable KMS encryption on the existing ECR repositories. Use AWS Trusted Advisor to check the

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    73% (36)
  • C
    6% (3)
  • D
    16% (8)

Explanation

https://docs.aws.amazon.com/AmazonECR/latest/userguide/repository-create.html https://docs.aws.amazon.com/AmazonECR/latest/userguide/repository-edit.html

Topics

#ECR encryption#KMS#container scanning#CVE detection

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice