Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 Docker image vulnerability scan Practice Question

A DevOps engineer needs to implement a CI/CD pipeline that builds a Docker image, scans it for vulnerabilities, and deploys it to Amazon ECS. The scanning must be integrated into the pipeline before the image is pushed to Amazon ECR. Which approach meets these requirements?

⚠ Common exam trap

A common mix-up: candidates confuse 'Scan on Push' (post-push) with pre-push scanning, or assume that Security Hub can directly scan and block deployments, when in reality it is an aggregation and correlation service, not a scanning engine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CodeBuild to run a vulnerability scanner on the Docker image, then push to ECR only if the scan passes.

It uses CodeBuild to run a vulnerability scanner on the Docker image before pushing to ECR, ensuring that only images that pass the scan are stored and deployed. This satisfies the requirement to scan before the image is pushed to ECR, which is critical for preventing vulnerable images from entering the registry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable ECR 'Scan on Push' and configure CodePipeline to deploy only if the scan result is clean.

    Why it's wrong here

    ECR Scan on Push only records findings after the image is pushed, and CodePipeline has no native action to parse scan results or conditionally block a deployment. A 'clean' gate would still require a custom Lambda or CodeBuild step to query findings, so this approach never provides a push-time safety barrier and adds post-hoc complexity.

  • ✓

    Use CodeBuild to run a vulnerability scanner on the Docker image, then push to ECR only if the scan passes.

    Why this is correct

    Running a scanner such as Trivy or Anchore inside a CodeBuild stage before the Docker push enforces a shift-left security gate; if the scanner exits with a non-zero code on critical/high vulnerabilities, the build fails and the image never reaches ECR. This keeps the registry free of vulnerable images and ensures only approved artifacts are available for subsequent pipeline stages.

  • ✗

    Use AWS Lambda to scan the image after push and automatically roll back if vulnerabilities are found.

    Why it's wrong here

    Scanning with Lambda after push is reactive and unsafe because the image is already in the registry and may have been deployed by the time findings are available. ECR offers no 'undo push' to roll back an image, and Lambda would need complex Docker image layer parsing to enumerate vulnerabilities, making it both fragile and operationally late.

  • ✗

    Use AWS Security Hub to scan images in ECR and block deployment.

    Why it's wrong here

    AWS Security Hub is an aggregation and post-discovery service, not a scanner or a policy enforcement point; it can collect Inspector findings for ECR images but has no ability to block a deployment or deny a Docker image. Relying on Security Hub to 'block' anything requires integrating with other services and still lacks the deterministic pre-push failure control that a CI/CD scanner provides.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The DOP-C02 exam frequently reuses these exact scenarios with slightly different constraints.

✓Use CodeBuild to run a vulnerability scanner on the Docker image, then push to ECR only if the scan passes.Correct answer▾

Why this is correct

Running a scanner such as Trivy or Anchore inside a CodeBuild stage before the Docker push enforces a shift-left security gate; if the scanner exits with a non-zero code on critical/high vulnerabilities, the build fails and the image never reaches ECR. This keeps the registry free of vulnerable images and ensures only approved artifacts are available for subsequent pipeline stages.

✗Enable ECR 'Scan on Push' and configure CodePipeline to deploy only if the scan result is clean.Wrong answer — click to see why▾

Why this is wrong here

Scan on Push scans after the image is pushed, not before. The requirement is to scan before push.

✗Use AWS Lambda to scan the image after push and automatically roll back if vulnerabilities are found.Wrong answer — click to see why▾

Why this is wrong here

This scans after push, not before.

✗Use AWS Security Hub to scan images in ECR and block deployment.Wrong answer — click to see why▾

Why this is wrong here

Security Hub aggregates findings but does not scan images itself; it relies on other services.

Analysis generated from the official DOP-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.