Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. Which permissions are required for the CodeBuild service role? (Choose THREE.)

⚠ Common exam trap

A common mix-up: candidates confuse `ecr:PutImage` with the non-existent `ecr:CreateImage` or mistakenly think `ecr:BatchGetImage` is needed for pushing, when in fact it is only used for pulling images.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ecr:PutImage

`ecr:PutImage` is the permission required to push a Docker image to an Amazon ECR repository. When CodeBuild completes a build and runs `docker push`, it calls the ECR API `PutImage` to upload the image manifest. Without this permission, the push operation will fail with an access denied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ecr:PutImage

    Why this is correct

    The `ecr:PutImage` permission is absolutely essential for CodeBuild to successfully publish a Docker image to an Amazon ECR repository. This API call is responsible for uploading the Docker image manifest and all its associated image layers, effectively registering the new image version within the specified repository and making it available for subsequent deployments or pulls.

  • ✓

    ecr:DescribeRepositories

    Why this is correct

    The `ecr:DescribeRepositories` permission is crucial for CodeBuild to verify the existence and status of the target ECR repository before attempting to push an image. This allows the build process to confirm that the designated repository is valid and accessible, preventing errors that would occur if the push target were misconfigured or did not exist, ensuring a robust build pipeline.

  • ✗

    ecr:CreateImage

    Why it's wrong here

    The `ecr:CreateImage` API action does not exist within the Amazon ECR service API. Docker images are not 'created' in ECR through a direct API call in this manner; instead, they are uploaded and registered using the `ecr:PutImage` action, which handles the manifest and layer data. Therefore, granting `ecr:CreateImage` permission is entirely irrelevant and will not facilitate the pushing of Docker images.

  • ✗

    ecr:BatchGetImage

    Why it's wrong here

    The `ecr:BatchGetImage` API action is specifically designed for retrieving (pulling) multiple Docker images or specific image layers from an ECR repository. Its primary purpose is to facilitate image consumption, not image publication. Consequently, this permission is entirely unrelated to the process of building and pushing a new Docker image to ECR from CodeBuild, as it serves the opposite function.

  • ✓

    ecr:GetAuthorizationToken

    Why this is correct

    The `ecr:GetAuthorizationToken` permission is fundamental for authenticating the Docker client within the CodeBuild environment with the Amazon ECR registry. This API call retrieves a temporary, short-lived authentication token that the Docker client then uses to log in to ECR. Without this token, subsequent Docker push commands to the ECR endpoint would fail due to a lack of proper authorization.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.