DOP-C02 SDLC Automation Practice Question
A company uses AWS CodeBuild to compile and test code. The buildspec.yaml includes a pre_build phase that runs 'aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin 123456789012.dkr.ecr.us-east-1.amazonaws.com'. The build fails with 'Error: Cannot connect to the Docker daemon'. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates may focus on the AWS CLI or ECR authentication syntax, missing that the fundamental issue is the Docker daemon not being available, which is a CodeBuild-specific configuration requirement for running Docker commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CodeBuild project does not have privileged mode enabled.
The error 'Cannot connect to the Docker daemon' indicates that the Docker daemon is not running or inaccessible within the CodeBuild build environment. CodeBuild runs Docker commands inside a container that does not have a Docker daemon by default. To execute Docker commands (such as docker login or docker build), the CodeBuild project must be configured with privileged mode enabled, which grants the container elevated permissions to run its own Docker daemon. Without privileged mode, any attempt to interact with the Docker daemon will fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The CodeBuild project does not have privileged mode enabled.
Why this is correct
In CodeBuild, Docker commands require access to a Docker daemon, but the default build environment runs as an unprivileged container without the necessary kernel capabilities (e.g., CAP_SYS_ADMIN) to start or use Docker. When privileged mode is not enabled, any Docker command such as `docker build` or `docker push` fails with permission errors or 'Cannot connect to the Docker daemon' because the daemon cannot run inside the container. Setting `PRIVILEGED_MODE=true` in the CodeBuild project environment (or via `PrivilegedMode: true` in infrastructure as code) is mandatory for Docker-based builds that need to build and push images to Amazon ECR.
- ✗
The region specified does not match the ECR repository region.
Why it's wrong here
This is not the root cause because the CodeBuild project specifies the same region as the Amazon ECR repository, so the Docker login should be able to reach the correct ECR endpoint. Even if there were a region mismatch, the failure would occur during the `docker login` step itself, not when running Docker commands during the build. The error described, related to Docker operations during compile/test, points to environment capabilities rather than regional authentication, which would be a separate 'login failed' or 'not authorized' message.
- ✗
The Docker login command syntax is incorrect.
Why it's wrong here
The ECR login syntax is actually correct, as the standard modern command uses `aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <registry>`. This is the official AWS CLI v2 pattern, replacing the deprecated `aws ecr get-login` command. If the syntax were wrong, you would see a credential or parameter validation error from `docker login` (e.g., 'login attempt to https://... failed')—not a Docker daemon connectivity error, which is what occurs when privileged mode is disabled.
- ✗
The AWS CLI is not installed in the CodeBuild environment.
Why it's wrong here
CodeBuild's managed build images (e.g., standard Amazon Linux 2, Ubuntu, or Windows images) include the AWS CLI preinstalled, so the CLI is always available unless a custom image explicitly removes it. If the AWS CLI were truly missing, the failure would appear during the pre-build phase as `aws: command not found` when attempting to run `aws ecr get-login-password`. Since the environment fails when executing Docker commands (likely `docker build` or `docker push`) after the login step, an installed CLI is confirmed and this is not a plausible cause.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.