Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company is using AWS CodeBuild as part of its CI/CD pipeline. The build projects need to access a private Amazon ECR repository to pull Docker images. What is the MOST secure way to grant CodeBuild access to ECR?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a service role for CodeBuild with an IAM policy that grants ECR pull access.

CodeBuild can assume an IAM service role with a policy that grants pull access to the ECR repository. This is the most secure approach because it avoids static credentials and leverages AWS identity and access management. Option A is wrong: a VPC endpoint provides private network connectivity to ECR but does not grant access; IAM permissions are still required. Option B is wrong: storing ECR credentials in Parameter Store introduces static credentials that must be managed and rotated, making it less secure than using an IAM role. Option D is wrong: using the AWS CLI to retrieve an authorization token requires managing temporary credentials and is more complex; the service role approach is simpler and more secure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a VPC endpoint for ECR and allow CodeBuild to connect through it.

    Why it's wrong here

    A VPC endpoint only establishes a private, secure network path between your VPC and ECR; it does not confer any IAM authorization. CodeBuild still needs explicit IAM permissions (e.g., ecr:GetAuthorizationToken, ecr:BatchGetImage) to interact with the repository. Even with the endpoint in place, a lack of identity-based or resource-based policy will result in AccessDenied. Therefore, connectivity alone does not solve the access-control problem.

  • ✗

    Store ECR credentials in AWS Systems Manager Parameter Store and retrieve them in the buildspec.

    Why it's wrong here

    Storing long-lived ECR credentials or authorization tokens in Parameter Store undermines the security of IAM-based authentication and requires manual rotation. ECR passwords and tokens are short-lived, so a static value will expire and break the pipeline. The recommended pattern is to assign a CodeBuild service role that supplies temporary credentials on demand, avoiding secret management and exposure in build logs. Retrieving secrets in buildspec adds complexity and risk compared to assuming an IAM role.

  • ✓

    Create a service role for CodeBuild with an IAM policy that grants ECR pull access.

    Why this is correct

    Creating a service role for CodeBuild and attaching an IAM policy with ECR pull permissions is the proper way to grant access. The service role is assumed by the CodeBuild build, and actions such as ecr:GetAuthorizationToken, ecr:BatchGetImage, and ecr:GetDownloadUrlForLayer allow Docker to pull the image. This approach uses temporary credentials and follows least-privilege principles, making it both secure and auditable. It is the only solution that directly addresses the permission requirement.

  • ✗

    Use the AWS CLI to retrieve an ECR authorization token and pass it to Docker.

    Why it's wrong here

    Running aws ecr get-login-password and docker login inside the build environment is a common implementation detail, but it does not itself grant any permissions; the CLI still needs valid AWS credentials to call the API. Those credentials would have to come from an IAM role or access keys, so this option is incomplete and adds manual token-handling steps. It also risks exposing the token in build logs and requires you to manage token expiry. The correct approach is to let CodeBuild's service role authenticate natively rather than handling tokens manually.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A DevOps engineer is troubleshooting a failed AWS CodeBuild project. The build fails with an error indicating that the IAM role does not have permission to describe Amazon ECR repositories. The role used by CodeBuild has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["ecr:GetAuthorizationToken","ecr:BatchCheckLayerAvailability","ecr:GetDownloadUrlForLayer","ecr:BatchGetImage"],"Resource":"*"}]}. What is the missing permission?

hard
  • A.ecr:InitiateLayerUpload
  • B.ecr:GetRepositoryPolicy
  • C.ecr:ListImages
  • ✓ D.ecr:DescribeRepositories

Why D: The error explicitly states the role lacks permission to 'describe Amazon ECR repositories,' which maps directly to the IAM action ecr:DescribeRepositories. This action is required by CodeBuild when it needs to verify the existence, URI, or configuration of an ECR repository before pulling an image. The existing policy only grants authentication and image-pull permissions (GetAuthorizationToken, BatchCheckLayerAvailability, GetDownloadUrlForLayer, BatchGetImage), none of which cover repository-level metadata inspection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.