QuestionQ35

Security and Compliance

A company is deploying a container-based application with AWS CodeBuild. The Security team requires that every container be scanned for vulnerabilities before deployment through a password-protected endpoint. All sensitive information must be securely stored.

Which solution should be used to satisfy these requirements?

Explanation

AWS Systems Manager Parameter Store can store the endpoint password as a SecureString, and AWS CodeBuild can retrieve that parameter at build time through the buildspec env/parameter-store mapping for use by the scanning command. CodeBuild documentation recommends Parameter Store or Secrets Manager rather than plaintext buildspec environment variables for sensitive values.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!