Courseiva
SDLC Automation →easyMultiple Select

DOP-C02 SDLC Automation Practice Question

A company is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. The buildspec.yaml includes commands to build and tag the image. However, the push to ECR fails with an authentication error. Which TWO actions should the DevOps engineer take to resolve this?

⚠ Common exam trap

A common mix-up: candidates think simply running `docker login` with static credentials (Option E) is sufficient, but they overlook that ECR requires a dynamically generated token via `get-login-password`, and that the CodeBuild service role must have the correct IAM permissions (Option D) for the authentication flow to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a command in the buildspec to run 'aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account>.dkr.ecr.<region>.amazonaws.com'.

The `aws ecr get-login-password` command retrieves a temporary authentication token from the ECR service, which is then piped to `docker login` to authenticate the Docker client against the private ECR registry. This is the standard AWS-recommended method for authenticating Docker to ECR in automated build environments like CodeBuild, as it avoids hardcoding long-lived credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the ECR repository as public.

    Why it's wrong here

    Making the ECR repository public changes its access control to permit unauthenticated pulls of images, but it does not alter how the Docker client authenticates for pushes. A public repository still requires valid AWS credentials and an authorization token to push an image, and the build is failing at the push/authentication stage, not at a lack of public access. Moreover, publishing the image publicly is likely an unintended security exposure, so this is neither a fix nor a safe workaround.

  • ✓

    Add a command in the buildspec to run 'aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account>.dkr.ecr.<region>.amazonaws.com'.

    Why this is correct

    This command is the standard way to authenticate Docker to an ECR registry. It invokes the AWS CLI to call ecr:GetAuthorizationToken, which returns a base64-encoded password valid for 12 hours, and pipes it directly to docker login using the --password-stdin flag to avoid exposing the token in process listings. The username must be AWS and the registry URL must include the account ID and region. With proper IAM permissions, this makes the subsequent docker push/build step succeed.

  • ✗

    Create an ECR lifecycle policy to expire untagged images.

    Why it's wrong here

    A lifecycle policy is an automated rule for cleaning up images after they have been pushed—for example, expiring untagged images after a few days to reduce storage costs. It has no effect on the build-time authentication or authorization process; it cannot supply a token or grant the CodeBuild service role permission to push. The error occurs before any image is pushed, so a lifecycle policy is irrelevant to the reported failure.

  • ✓

    Ensure the CodeBuild service role has permissions for ecr:GetAuthorizationToken and ecr:Push.

    Why this is correct

    The CodeBuild service role must have an IAM policy that includes ecr:GetAuthorizationToken to generate the Docker login password and ecr:Push (along with ecr:BatchGetImage and other push-related actions) to upload the image to the repository. If these permissions are missing, the aws ecr get-login-password call or the docker push will fail even with a correct buildspec. Therefore, verifying and attaching the correct IAM permissions is an essential part of the solution, not an optional step.

  • ✗

    Run 'docker login' with ECR credentials in the buildspec.

    Why it's wrong here

    Attempting to run docker login with a literal username and password for ECR is incorrect because ECR does not use a fixed, persistent registry password. The only valid credentials are short-lived authorization tokens obtained from the AWS CLI's get-login-password command. Hardcoding any password in the buildspec would be a security liability and, more fundamentally, would not authenticate because ECR expects the dynamically generated token as the password.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS CodeBuild to build a Docker image and push it to Amazon ECR. The buildspec.yml includes a 'post_build' phase command to tag the image. The build fails with 'unauthorized: authentication required'. What must be done to resolve this?

easy
  • ✓ A.Add 'ecr:InitiateLayerUpload' and 'ecr:CompleteLayerUpload' permissions to the CodeBuild service role.
  • B.Use the 'docker login' command with AWS CLI in the build phase.
  • C.Install the AWS CLI in the CodeBuild build environment.
  • D.Create a new IAM user with ECR permissions and store the keys in CodeBuild environment variables.

Why A: The error 'unauthorized: authentication required' indicates that CodeBuild's IAM role lacks the necessary permissions to push the Docker image to Amazon ECR. The correct resolution is to add the specific ECR permissions 'ecr:InitiateLayerUpload' and 'ecr:CompleteLayerUpload' to the CodeBuild service role, as these are required for the Docker push operation to upload image layers. Without these permissions, the ECR API rejects the push even if other permissions like 'ecr:GetAuthorizationToken' are present.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.