A company is deploying a container-based application with AWS CodeBuild. The Security team requires that every container be scanned for vulnerabilities before deployment through a password-protected endpoint. All sensitive information must be securely stored.
Which solution should be used to satisfy these requirements?
A Encrypt the password using AWS KMS. Store the encrypted password in the buildspec.yml file as an environment variable under the variables mapping. Reference the environment variable to initiate scanning. B Import the password into an AWS CloudHSM key. Reference the CloudHSM key in the buildpec.yml file as an environment variable under the variables mapping. Reference the environment variable to initiate scanning. C Store the password in the AWS Systems Manager Parameter Store as a secure string. Add the Parameter Store key to the buildspec.yml file as an environment variable under the parameter-store mapping. Reference the environment variable to initiate scanning. D Use the AWS Encryption SDK to encrypt the password and embed in the buildspec.yml file as a variable under the secrets mapping. Attach a policy to CodeBuild to enable access to the required decryption key. Show Answer Answer Explanation AWS Systems Manager Parameter Store can store the endpoint password as a SecureString, and AWS CodeBuild can retrieve that parameter at build time through the buildspec env/parameter-store mapping for use by the scanning command. CodeBuild documentation recommends Parameter Store or Secrets Manager rather than plaintext buildspec environment variables for sensitive values.
Learn more
Community Discussion