DOP-C02 Incident and Event Response Practice Question
A company runs a containerized microservices application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer to route traffic to the ECS service. Recently, the DevOps team noticed that the ECS service is failing to deploy new tasks during a rolling update. The CloudWatch Logs for the ECS service show that new tasks are failing to start because they cannot pull the container image from Amazon ECR. The error message indicates 'AccessDenied' when attempting to pull the image. The task execution role has the necessary permissions, and the image URI is correct. The VPC has a VPC endpoint for ECR configured. The security group for the tasks allows outbound traffic to the VPC endpoint. What is the MOST likely cause of the access denied error?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VPC endpoint for ECR does not have 'Private DNS names enabled' selected.
For ECS tasks using Fargate to pull images from ECR via a VPC endpoint, the private DNS names must be enabled on the endpoint. If not enabled, the task's DNS resolution of the ECR repository URL returns a public IP, which may be blocked by security groups or route tables, causing an 'AccessDenied' error despite correct IAM permissions. Option A is incorrect because 'ecr:GetAuthorizationToken' is needed for authentication, but the error occurs after authentication (the task execution role has permissions). Option B is irrelevant as the ALB security group does not affect image pulling. Option D is incorrect because the task role is for application-level permissions, not for pulling images; that is handled by the task execution role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The task execution role does not have the 'ecr:GetAuthorizationToken' permission.
Why it's wrong here
The error is an 'AccessDenied' that occurs during ECS's image pull phase, and the team has already confirmed the task execution role contains 'ecr:GetAuthorizationToken'. Even if that permission were missing, ECS would report an explicit authorization failure; however, the real cause is that the VPC endpoint's private DNS setting is disabled, so traffic resolves to public ECR IPs that the private subnets cannot reach, yielding an AccessDenied from the endpoint rather than an IAM denial.
- ✗
The security group for the ALB does not allow inbound traffic to the ECS tasks.
Why it's wrong here
The ALB security group governs traffic between the load balancer and the ECS tasks, not the outbound request from the ECS agent to Amazon ECR. The error occurs in the PullImage step, before the task is even launched and long before the ALB forwards any client traffic, so a security group rule on the ALB has no bearing on image retrieval. Furthermore, security groups are stateful and do not block outbound connections originating from the task or agent unless a specific egress rule is missing, which is not implied here.
- ✓
The VPC endpoint for ECR does not have 'Private DNS names enabled' selected.
Why this is correct
When the 'Private DNS names enabled' option is not selected for an Amazon ECR VPC endpoint, the default DNS endpoint (ecr.<region>.amazonaws.com) continues to resolve to public IP addresses. Since the ECS task runs in a private subnet with no internet route, the ECS agent sends the request to a public IP that is unreachable, and the VPC endpoint responds with AccessDenied because the request is not being handled by the endpoint. Enabling private DNS names creates a Route 53 private hosted zone that associates the endpoint's DNS with its private IP, ensuring traffic destined for ECR is routed through the VPC endpoint and bypasses the public network.
- ✗
The task role does not have the 'ecr:BatchGetImage' permission.
Why it's wrong here
The task role is assumed by the application containers inside the running task, not by the ECS agent that performs image pulls. The ECS agent uses the task execution role to call ecr:GetAuthorizationToken and ecr:BatchGetImage; the task role is only relevant for the application's runtime access to AWS services. Additionally, the failure occurs during the state transition before the task is instantiated, so the task role is never even assumed at that point.
Visual reference
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.