A company uses Amazon Elastic Container Registry (Amazon ECR) for all images in the company’s containerized infrastructure. The company uses pull-through cache functionality with the `/external` prefix to avoid throttling when retrieving images from external image registries. The company uses AWS Organizations for its accounts. Every image in the registry must be encrypted with a specific, pre-provisioned AWS Key Management Service (AWS KMS) key. The company’s internally created images already comply with this policy. However, cached external images use server-side encryption with Amazon S3 managed keys (SSE-S3). The company must remove the noncompliant cache repositories. The company must also implement a secure solution so that all new pull-through cache repositories are automatically encrypted with the required KMS key. Which solution meets these requirements?