DVA-C02 Deployment Practice Question
A developer is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. The build fails with a 'no basic auth credentials' error when trying to push the image. Which TWO actions should the developer take to resolve this issue? (Choose two.)
⚠ Common exam trap
Many exam-takers assume the issue is missing Docker or AWS CLI installations, overlooking that both are pre-installed in CodeBuild, and instead fail to recognize the need for explicit authentication and IAM permissions for ECR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a pre-build command to run 'aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account-id>.dkr.ecr.<region>.amazonaws.com'.
The 'aws ecr get-login-password' command retrieves a temporary authentication token from AWS, which is then piped to 'docker login' to authenticate the Docker client with the Amazon ECR registry. This is the standard method for authenticating Docker to ECR, and it must be executed in the pre-build phase to ensure credentials are available before the 'docker push' command runs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a pre-build command to run 'aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account-id>.dkr.ecr.<region>.amazonaws.com'.
Why this is correct
For CodeBuild to successfully push a Docker image to Amazon ECR, the Docker daemon running within the build environment must first authenticate with the ECR registry. This pre-build command retrieves a temporary authorization token from ECR using the AWS CLI's 'get-login-password' command and pipes it directly to 'docker login', securely authenticating the Docker client for subsequent push operations. This is a mandatory step to establish a trusted connection.
- ✗
Install the AWS CLI in the buildspec.yml file.
Why it's wrong here
AWS CodeBuild environments are pre-configured with essential development tools, including the AWS Command Line Interface (CLI). Attempting to install the AWS CLI again within the `buildspec.yml` file is redundant and unnecessary. This action would consume valuable build time and bandwidth without providing any additional functionality, as the CLI is already available for use.
- ✗
Install Docker in the buildspec.yml file.
Why it's wrong here
AWS CodeBuild environments are specifically designed to support containerized workloads and come with Docker pre-installed and running. The Docker daemon and client are readily available for use within the build container, allowing developers to build and push Docker images without needing to explicitly install Docker in their `buildspec.yml` file. Installing it again would be a superfluous and inefficient step.
- ✓
Add an IAM policy to the CodeBuild service role that allows ecr:GetAuthorizationToken and ecr:Push.
Why this is correct
For the CodeBuild project to interact with Amazon ECR, its associated service role requires explicit AWS Identity and Access Management (IAM) permissions. Specifically, `ecr:GetAuthorizationToken` is necessary to retrieve the temporary login credentials used by the Docker client, and `ecr:PutImage` (often conceptually grouped as `ecr:Push`) is required to upload the built Docker image layers and manifest to the designated ECR repository. Without these permissions, the CodeBuild project will be unauthorized to perform these actions, leading to build failures.
- ✗
Configure SSH key-based authentication for ECR.
Why it's wrong here
Amazon ECR utilizes AWS Identity and Access Management (IAM) for all authentication and authorization purposes, integrating seamlessly with AWS's native security model. ECR does not support or recognize SSH key-based authentication, which is typically used for secure shell access to compute instances or Git repositories. Attempting to configure SSH keys for ECR would be fundamentally incompatible with its security architecture and would not enable image pushes.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.