A company wants to enforce that every container image deployed to ECS was built by their CodeBuild pipeline and has not been tampered with. Which AWS service enforces this?
-
A
Amazon Inspector container scanning integrated with CodePipeline
-
B
AWS Signer with container image signing and ECR image tag immutability
-
C
Amazon Macie monitoring ECR repositories for sensitive data
-
D
AWS Config rule checking ECS task definition image URIs