Q: 10
A company creates AWS Lambda functions from container images that are stored in Amazon Elastic
Container Registry (Amazon ECR). The company needs to identify any software vulnerabilities in the
container images and any code vulnerabilities in the Lambda functions.
Which solution will meet these requirements?
Options
Discussion
Option C fits best here. Inspector is the specific AWS service that does vulnerability scans on both ECR images and Lambda code. B (GuardDuty) is tempting, but that's more about threat detection and runtime monitoring, not actual code or image vuln scanning. Pretty sure the key words are "identify vulnerabilities" not just monitor. Anyone see anything in the docs suggesting otherwise?
B tbh, had something like this on a mock and B was picked for Lambda/runtime protection.
C for sure, Inspector actually does the scanning for both ECR images and Lambda code. Saw a similar question pop up in practice exams. GuardDuty is more about runtime threats, not vuln scans. Pretty confident but open if AWS changed something!
Why do folks keep picking B for Lambda code scans? Inspector is actually the one scanning both ECR images and Lambda code, not GuardDuty.
Why are these AWS security options always so confusing? Does Inspector really scan Lambda code or just containers?
C since Amazon Inspector does actual vulnerability scanning for both ECR images and Lambda code. Official docs and practice tests highlight this. Not totally sure, but that's what I've seen in recent exam topics.
B not C
Why not B for pure runtime threats? Lambda code scanning isn't GuardDuty's thing, right?
Its C, since Inspector does both ECR image scanning and Lambda code scanning for vulnerabilities. GuardDuty (B) is more for runtime threats, not actual vuln scans. Pretty sure that’s what the question wants but let me know if I missed anything.
B. not C
Be respectful. No spam.