DVA-C02 Security Practice Question
A company is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. Which permissions are required for the CodeBuild service role? (Choose THREE.)
⚠ Common exam trap
A common mix-up: candidates confuse `ecr:PutImage` with the non-existent `ecr:CreateImage` or mistakenly think `ecr:BatchGetImage` is needed for pushing, when in fact it is only used for pulling images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ecr:PutImage
`ecr:PutImage` is the permission required to push a Docker image to an Amazon ECR repository. When CodeBuild completes a build and runs `docker push`, it calls the ECR API `PutImage` to upload the image manifest. Without this permission, the push operation will fail with an access denied error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ecr:PutImage
Why this is correct
The `ecr:PutImage` permission is absolutely essential for CodeBuild to successfully publish a Docker image to an Amazon ECR repository. This API call is responsible for uploading the Docker image manifest and all its associated image layers, effectively registering the new image version within the specified repository and making it available for subsequent deployments or pulls.
- ✓
ecr:DescribeRepositories
Why this is correct
The `ecr:DescribeRepositories` permission is crucial for CodeBuild to verify the existence and status of the target ECR repository before attempting to push an image. This allows the build process to confirm that the designated repository is valid and accessible, preventing errors that would occur if the push target were misconfigured or did not exist, ensuring a robust build pipeline.
- ✗
ecr:CreateImage
Why it's wrong here
The `ecr:CreateImage` API action does not exist within the Amazon ECR service API. Docker images are not 'created' in ECR through a direct API call in this manner; instead, they are uploaded and registered using the `ecr:PutImage` action, which handles the manifest and layer data. Therefore, granting `ecr:CreateImage` permission is entirely irrelevant and will not facilitate the pushing of Docker images.
- ✗
ecr:BatchGetImage
Why it's wrong here
The `ecr:BatchGetImage` API action is specifically designed for retrieving (pulling) multiple Docker images or specific image layers from an ECR repository. Its primary purpose is to facilitate image consumption, not image publication. Consequently, this permission is entirely unrelated to the process of building and pushing a new Docker image to ECR from CodeBuild, as it serves the opposite function.
- ✓
ecr:GetAuthorizationToken
Why this is correct
The `ecr:GetAuthorizationToken` permission is fundamental for authenticating the Docker client within the CodeBuild environment with the Amazon ECR registry. This API call retrieves a temporary, short-lived authentication token that the Docker client then uses to log in to ECR. Without this token, subsequent Docker push commands to the ECR endpoint would fail due to a lack of proper authorization.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.