DOP-C02 SDLC Automation Practice Question
A company uses AWS CodeBuild to run security scans. The scans require access to a private Amazon ECR repository. The build project is configured with a service role. What is the correct way to provide access to ECR?
⚠ Common exam trap
Candidates often think they need to embed credentials (options A or C) or rely on another service's role (option B), when the correct approach is to attach the necessary IAM policy directly to the CodeBuild service role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to the CodeBuild service role that allows ECR operations.
CodeBuild uses an IAM service role to define the permissions granted to the build environment. By attaching an IAM policy that allows ECR operations (such as ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, and ecr:GetAuthorizationToken) to the CodeBuild service role, the build project can authenticate and pull images from the private ECR repository without needing to embed or manage static credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set environment variables with ECR credentials in the build project.
Why it's wrong here
Setting environment variables in the CodeBuild project to hold ECR credentials embeds long-lived static access keys, which is insecure, hard to rotate, and prone to accidental exposure in console views or CloudWatch logs. CodeBuild should instead rely on the IAM service role it assumes at build time, allowing it to call ecr:GetAuthorizationToken and obtain short-lived credentials automatically. Environment variables are not a substitute for IAM permissions in a secure AWS architecture.
- ✗
Configure the ECR repository policy to allow access from the CodePipeline service role.
Why it's wrong here
The CodePipeline service role is used to orchestrate pipeline stages but is not the identity invoked when CodeBuild fetches the container image from ECR. The ECR repository policy should be scoped to the CodeBuild project's service role ARN, or the equivalent IAM permissions should be attached to that role, to authorize the build action. Granting access to the CodePipeline role would be useless because it never acts as the build runner and cannot authenticate the actual image pull.
- ✗
Include the ECR credentials in the buildspec file.
Why it's wrong here
Hard-coding ECR credentials in the buildspec file stores secrets in source control or build artifacts, creating a severe leakage risk and making credential rotation impractical. Even if the buildspec is stored only in S3, anyone with read access to that object can extract the credentials and reuse them outside the build. A CodeBuild service role with ECR permissions eliminates the need for stored credentials, since aws ecr get-login-password uses the role's temporary keys and returns a short-lived token by default.
- ✓
Attach an IAM policy to the CodeBuild service role that allows ECR operations.
Why this is correct
Attaching an IAM policy to the CodeBuild service role is the correct approach because CodeBuild assumes this role during the build and uses it to authorize ECR actions such as ecr:GetAuthorizationToken, ecr:BatchGetImage, and ecr:GetDownloadUrlForLayer. This gives the build project exactly the permissions it needs, following least privilege, without exposing static credentials in environment variables or source files. The service role is the native and secure identity for CodeBuild to interact with AWS resources like ECR.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.