DOP-C02 Security and Compliance Practice Question
A DevOps engineer manages a CI/CD pipeline that builds Docker images and pushes them to Amazon ECR. The security team requires that every image be scanned for known vulnerabilities before deployment, and that the pipeline fail if any critical severity findings are detected. The engineer enables scan on push for the repository. Which additional step must be added to the pipeline to meet the requirement?
⚠ Common exam trap
The trap here is assuming that enabling scan on push automatically blocks vulnerable images from being pushed or deployed, when it only produces findings that must be evaluated separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the ECR DescribeImageScanFindings API to retrieve the scan results and fail the pipeline if any finding has a severity of CRITICAL.
ECR scan on push generates vulnerability findings but does not enforce any action. To gate the pipeline, the engineer must call DescribeImageScanFindings after the push and evaluate the severity counts. If any CRITICAL finding exists, the pipeline should fail. This is the standard pattern for integrating ECR image scanning into a CI/CD workflow and meets the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config to evaluate the ECR image scan results and trigger an AWS Lambda function that stops the pipeline.
Why it's wrong here
AWS Config evaluates resource configurations, not the vulnerability findings of container images. There is no managed rule that inspects ECR scan findings for critical severity. Using Config would add unnecessary complexity and would not reliably fail the pipeline at the right moment, so it does not satisfy the requirement.
- ✗
Configure the ECR repository to block pushes of images that contain critical vulnerabilities.
Why it's wrong here
Amazon ECR does not provide a repository setting that blocks image pushes based on scan results. Scan on push only generates findings; it does not prevent the image from being stored. The pipeline must inspect the findings and decide whether to proceed, so this option does not meet the requirement.
- ✓
Use the ECR DescribeImageScanFindings API to retrieve the scan results and fail the pipeline if any finding has a severity of CRITICAL.
Why this is correct
Enabling scan on push only initiates the scan; the pipeline must actively retrieve the results. Calling DescribeImageScanFindings returns the severity counts and individual findings, allowing the pipeline to evaluate them and fail when CRITICAL findings exist. This directly satisfies the requirement to block deployment based on critical vulnerabilities.
- ✗
Enable Amazon Inspector and configure it to fail the CodePipeline stage when critical findings are detected.
Why it's wrong here
Amazon Inspector does not natively integrate with CodePipeline to fail a stage based on container image findings. While Inspector can scan certain workloads, it is not the mechanism that evaluates ECR scan results within a pipeline. The pipeline must explicitly check ECR findings to enforce the gate.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.