Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

A developer is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. The build fails with the error 'no basic authentication credentials'. The build project has an IAM role with the AmazonEC2ContainerRegistryPowerUser policy. What is the most likely cause?

⚠ Common exam trap

DVA-C02 often tests the misconception that granting an IAM policy like AmazonEC2ContainerRegistryPowerUser is sufficient for Docker to push to ECR, when in fact the buildspec must explicitly authenticate the Docker client.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The buildspec does not include the pre_build step to authenticate with ECR.

AWS CodeBuild does not automatically authenticate to Amazon ECR. The buildspec must include a pre_build phase that runs 'aws ecr get-login-password' piped to 'docker login' (or uses the ECR credential helper) to obtain temporary credentials. The IAM role's AmazonEC2ContainerRegistryPowerUser policy grants the necessary permissions, but the Docker client still needs explicit authentication before pushing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The build project is not configured to use a VPC that can reach ECR.

    Why it's wrong here

    Amazon ECR is a public regional AWS API endpoint reachable over the internet or through a VPC interface endpoint; CodeBuild does not require VPC connectivity to reach ECR unless the build project is deliberately configured inside a private VPC with no NAT or endpoint, and this scenario gives no indication of custom VPC configuration causing the failure.

  • ✗

    The build environment does not have Docker installed.

    Why it's wrong here

    AWS CodeBuild's managed build images (such as the standard aws/codebuild/standard images) come with Docker pre-installed and support Docker-in-Docker builds when privileged mode is enabled, so a missing Docker binary would produce a 'docker: command not found' error, not the 'no basic authentication credentials' error described here.

  • ✗

    The IAM role does not have sufficient permissions to push to ECR.

    Why it's wrong here

    The AmazonEC2ContainerRegistryPowerUser policy already grants ECR push permissions, so the role is not the cause. The 'no basic authentication credentials' error arises because CodeBuild cannot authenticate to ECR; the fix is granting ecr:GetAuthorizationToken or using the ECR login helper. This option tempts those assuming missing IAM rights.

  • ✓

    The buildspec does not include the pre_build step to authenticate with ECR.

    Why this is correct

    The 'no basic authentication credentials' error occurs specifically when the Docker client attempts to push to ECR without first authenticating; the buildspec must include a pre_build phase command that runs 'aws ecr get-login-password | docker login' to obtain a temporary token, and omitting this step is the classic root cause of this exact error message.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.