DOP-C02 SDLC Automation Practice Question
A company uses AWS CodeBuild to run security scans on code. The scan requires access to a private Amazon ECR repository for downloading scanning tools. The CodeBuild project is configured with a VPC and uses an IAM role. However, the build fails with 'Error: unable to pull image from registry.' Which TWO steps should be taken to resolve this?
⚠ Common exam trap
The trap here is that candidates often focus solely on IAM permissions (Option C) and overlook the VPC endpoint requirement (Option E), or they incorrectly assume removing the VPC (Option B) is the fix, not realizing that VPC endpoints are the correct way to provide private connectivity to ECR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'ecr:GetDownloadUrlForLayer' and 'ecr:BatchGetImage' permissions to the CodeBuild service role.
The CodeBuild service role must have the 'ecr:GetDownloadUrlForLayer' and 'ecr:BatchGetImage' permissions to authorize the retrieval of container image layers from the private ECR repository. Without these permissions, the Docker pull operation fails with 'unable to pull image from registry' even if network connectivity is established.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the ECR repository policy to allow public access.
Why it's wrong here
Allowing public access to the ECR repository would grant unauthenticated users the ability to pull images, exposing proprietary code and potentially leaked secrets to the entire internet. It also doesn't resolve the CodeBuild pipeline's IAM authorization failure, because even with a public repository policy, the CodeBuild service role still needs explicit permissions to call ECR APIs and receive the image manifest and layers. Thus, this introduces a major security vulnerability while failing to address the actual missing permission issue.
- ✗
Remove the VPC configuration from the CodeBuild project so it can access the public internet.
Why it's wrong here
Removing the VPC configuration from the CodeBuild project might allow it to reach the public internet if the VPC lacked a NAT gateway, but it does not grant any ECR IAM permissions, so the build would still fail with an unauthorized error. Additionally, tearing down the VPC configuration removes network isolation and could force the build environment to communicate over the public internet, which is a security regression and often violates compliance policies. The correct fix is to add the missing ECR API actions to the service role.
- ✓
Add 'ecr:GetDownloadUrlForLayer' and 'ecr:BatchGetImage' permissions to the CodeBuild service role.
Why this is correct
The CodeBuild service role must include ecr:GetDownloadUrlForLayer and ecr:BatchGetImage, along with ecr:GetAuthorizationToken, to successfully pull a container image from Amazon ECR. BatchGetImage retrieves the image manifest, while GetDownloadUrlForLayer obtains the URLs for each layer, and both are required after CodeBuild calls GetAuthorizationToken to authenticate. Without these permissions, CodeBuild receives an AccessDenied exception and the security scan cannot start.
- ✗
Grant 'kms:Decrypt' permissions for the KMS key used by ECR.
Why it's wrong here
Granting kms:Decrypt is only relevant if the ECR repository is configured with a customer-managed KMS key for image encryption; the default aws/ecr encryption uses an AWS-managed key that requires no separate KMS permissions from the puller. Even when a customer-managed key is used, IAM must also allow the ECR image pull actions, and the primary observed error is almost certainly missing ecr:BatchGetImage/GetDownloadUrlForLayer rather than KMS. Therefore, this change does not address the root cause and may be unnecessary.
- ✓
Create a VPC endpoint for Amazon ECR and associate it with the VPC used by CodeBuild.
Why this is correct
Creating an ECR VPC endpoint is a correct configuration step when CodeBuild runs in a VPC: it enables private connectivity between the VPC and ECR without traversing the internet, using AWS PrivateLink. However, the VPC endpoint only handles network-level routing and DNS; the CodeBuild role still requires IAM permissions to authorize the ECR pull operation. So while this should be done for a private and secure setup, it is complementary to, not a replacement for, the missing permission.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.