AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company must deliver an updated, hardened Docker image for a Java microservice every month. The solution must automatically start from the latest public Amazon Corretto base image, install OS patches and application libraries, run functional tests, perform a vulnerability scan, and then push the approved image to an existing Amazon ECR repository. Operations wants an AWS-managed solution that requires the least ongoing maintenance. Which approach meets these requirements?
Use AWS App2Container to repackage the Java application and rely on Amazon ECS to pull the latest image at deployment time.
Configure a weekly Amazon EventBridge rule to trigger an AWS CodeBuild project that executes docker build and docker push commands and runs an open-source vulnerability scanner inside the buildspec.
Create an EC2 Image Builder container pipeline with a container recipe that extends the Amazon Corretto base image, adds the application layers and tests, sets the ECR repository as the distribution target, and enable Amazon Inspector scanning on the registry.
Run a Jenkins server on Amazon EC2 that executes a pipeline to build, test, scan, and push the image to ECR on a cron schedule.
EC2 Image Builder natively supports container pipelines. A container recipe can extend a public Amazon Corretto base image, run build and test components that apply updates, and then distribute the resulting image directly to an Amazon ECR repository. When Amazon Inspector container scanning is enabled on the registry, every pushed image is automatically scanned for CVEs, satisfying the vulnerability-assessment requirement without additional custom code. The entire workflow is managed and scheduled by Image Builder, so no servers or bespoke build scripts need to be maintained. The other options rely on self-managed tooling (Jenkins), custom buildspecs, or repurposing App2Container, all of which introduce additional operational overhead and complexity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EC2 Image Builder, and how does it support container pipelines?
Open an interactive chat with Bash
How does Amazon Inspector integrate with Amazon ECR to perform vulnerability scans?
Open an interactive chat with Bash
Why are the other proposed solutions less optimal compared to EC2 Image Builder?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .