An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.2.3. Amazon Inspector and Common Assessment Templates

3.2.2.3. Amazon Inspector and Common Assessment Templates

Amazon Inspector scans for vulnerabilities automatically — on EC2 instances, ECR container images, and Lambda functions.

Inspector v2 (current version) is agentless for ECR and Lambda. For EC2, it uses the SSM Agent (already installed on most modern AMIs).

What Inspector scans:
TargetVulnerability TypeTrigger
EC2 instancesCVEs in OS packages, network reachabilityContinuous (event-driven)
ECR imagesCVEs in OS and language packagesOn push + continuous re-scan
Lambda functionsCVEs in language packagesOn deploy + continuous

Inspector findings include CVE ID, severity (Critical/High/Medium/Low), affected package, and fix recommendation. Findings are sent to Security Hub for centralized management. Inspector produces three finding types: Package vulnerability (CVEs in OS and language packages), Code vulnerability (optional Lambda code scanning — injection flaws, data leaks, hardcoded secrets) and Network reachability (EC2 ports reachable from outside). Malware is GuardDuty's job, over-permissive IAM is IAM Access Analyzer's, and configuration drift is AWS Config's. To prioritize, fix Critical and High first, then rank the rest by the Inspector score — the CVSS base score adjusted for your environment (e.g., network reachability, exploit availability).

Integration with CI/CD: Scan ECR images on push and block deployment if Critical/High vulnerabilities are found. Use EventBridge to trigger a Lambda function that checks Inspector findings before CodePipeline proceeds.

# Check Inspector findings for a specific ECR image
aws inspector2 list-findings \
  --filter-criteria '{
    "resourceType": [{"comparison": "EQUALS", "value": "AWS_ECR_CONTAINER_IMAGE"}],
    "severity": [{"comparison": "EQUALS", "value": "CRITICAL"}],
    "ecrImageRepositoryName": [{"comparison": "EQUALS", "value": "my-app"}]
  }'

Exam Trap: Inspector v2 replaced Inspector Classic (which used assessment templates, a separately installed agent, and scheduled assessment runs). Inspector Classic reached end of support on May 20, 2026, but the exam guide still says "assessment templates", so recognize the term as Classic. Inspector v2 scans continuously and doesn't use templates, so for any current scanning requirement the answer is Amazon Inspector's continuous scanning.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications