DOP-C02 SDLC Automation Practice Question
A DevOps engineer is tasked with automating the deployment of a microservices architecture. Each service is packaged as a Docker container. The team wants to use AWS CodePipeline and AWS CodeBuild to build Docker images and push them to Amazon ECR, then deploy to Amazon ECS. What should the CodeBuild buildspec file include to push the image to ECR?
⚠ Common exam trap
Many candidates assume CodeBuild has a native 'ecr-push' action or that ECS APIs are involved in image pushing, when in fact the process relies on standard Docker commands and AWS CLI authentication within the buildspec.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Docker build and docker push commands with AWS CLI to authenticate to ECR.
To push a Docker image to Amazon ECR, the buildspec must first authenticate Docker to the ECR registry using the AWS CLI's `aws ecr get-login-password` command piped to `docker login`, then build the image with `docker build`, tag it with the ECR repository URI, and finally push it with `docker push`. CodeBuild does not have a built-in 'ecr-push' action; it relies on executing these standard Docker and AWS CLI commands in the build phases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A call to the AWS CodeDeploy API to push the image.
Why it's wrong here
The AWS CodeDeploy API is designed to orchestrate application deployments to EC2 instances, Lambda functions, or Amazon ECS services, not to transfer container images. CodeDeploy has no method that accepts image bytes or pushes to Elastic Container Registry; its deployment actions simply reference an already-published artifact. Therefore, calling CodeDeploy cannot automate the push step.
- ✗
An invocation of the AWS ECS RunTask API.
Why it's wrong here
The ECS RunTask API launches an individual task from a task definition, which must already reference a Docker image URI in ECR or another registry. It does not perform any registry write operation, and it will fail if the image does not already exist because ECS will attempt to pull rather than push. Thus, RunTask is an execution operation, not an ingestion operation, so it cannot replace docker push.
- ✗
A buildspec phase with 'ecr-push' action.
Why it's wrong here
CodeBuild buildspec is a YAML document with defined phases (install, pre_build, build, post_build), and there is no declarative action named 'ecr-push' that the build runner understands. Image publishing must be implemented as ordinary shell commands within those phases, typically using AWS CLI and Docker CLI. A hypothetical 'ecr-push' action would not be recognized and would cause a build failure.
- ✓
Docker build and docker push commands with AWS CLI to authenticate to ECR.
Why this is correct
The correct approach is to authenticate the local Docker daemon to the private ECR registry using 'aws ecr get-login-password' piped to 'docker login', then build your image with 'docker build', tag it with the ECR repository URI, and run 'docker push'. This satisfies ECR's token-based authentication and uploads Docker layers directly to the registry's S3-backed storage. It is the only way among the choices that actually moves image data into ECR.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.