Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer is troubleshooting a failed AWS CodeBuild project. The build fails with an error indicating that the IAM role does not have permission to describe Amazon ECR repositories. The role used by CodeBuild has the following policy attached: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["ecr:GetAuthorizationToken","ecr:BatchCheckLayerAvailability","ecr:GetDownloadUrlForLayer","ecr:BatchGetImage"],"Resource":"*"}]}. What is the missing permission?

⚠ Common exam trap

DOP-C02 often tests the confusion between ECR control-plane actions (DescribeRepositories, GetRepositoryPolicy, ListImages) and data-plane pull/push actions (BatchGetImage, GetDownloadUrlForLayer, InitiateLayerUpload), tricking candidates into selecting a related-sounding but incorrect ECR permission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ecr:DescribeRepositories

The error explicitly states the role lacks permission to 'describe Amazon ECR repositories,' which maps directly to the IAM action ecr:DescribeRepositories. This action is required by CodeBuild when it needs to verify the existence, URI, or configuration of an ECR repository before pulling an image. The existing policy only grants authentication and image-pull permissions (GetAuthorizationToken, BatchCheckLayerAvailability, GetDownloadUrlForLayer, BatchGetImage), none of which cover repository-level metadata inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ecr:InitiateLayerUpload

    Why it's wrong here

    ecr:InitiateLayerUpload is part of the ECR image-push lifecycle (InitiateLayerUpload, UploadLayerPart, CompleteLayerUpload), used to start uploading a new image layer. It is a write-oriented action and grants no ability to read or list repository metadata. CodeBuild calling describe-repositories would not require this action, so its absence cannot be the cause of the failure.

  • ✗

    ecr:GetRepositoryPolicy

    Why it's wrong here

    ecr:GetRepositoryPolicy retrieves the resource-based IAM policy attached to a specific repository, analogous to reading an S3 bucket policy. It returns only the policy document, not repository attributes such as ARN, URI, creation date, or image scan configuration. Since the failing operation is repository enumeration/metadata, the required permission is ecr:DescribeRepositories, not GetRepositoryPolicy.

  • ✗

    ecr:ListImages

    Why it's wrong here

    ecr:ListImages returns image identifiers (tags and digests) for images inside a repository, but only after you have already specified or selected that repository. It does not provide repository-level metadata like the registry ID, repository ARN, or repository URI. Describing repositories themselves is a distinct operation that requires ecr:DescribeRepositories, making ListImages insufficient and incorrect.

  • ✓

    ecr:DescribeRepositories

    Why this is correct

    ecr:DescribeRepositories is the exact IAM action required to call the ECR DescribeRepositories API, which CodeBuild uses to list repositories and retrieve their metadata (repository name, ARN, URI, creation timestamp, and image scanning configuration). If this permission is missing from the CodeBuild service role, any attempt to enumerate or describe repositories will fail with AccessDenied. This is the root cause of the failure in the scenario.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.