DOP-C02 Configuration Management and IaC Practice Question
A DevOps engineer is using AWS CodeBuild to build a container image and push it to Amazon ECR. The buildspec.yml file includes a post_build phase that runs `docker push`. The build fails with an error indicating that the Docker daemon is not available. The CodeBuild project uses the `aws/codebuild/standard:5.0` image and has privileged mode disabled. Which action should the engineer take to resolve the issue?
⚠ Common exam trap
The trap here is assuming that Docker can run in CodeBuild without privileged mode, leading to attempts to start the daemon manually or change images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable privileged mode in the CodeBuild project configuration.
Docker requires privileged mode in CodeBuild to run the Docker daemon. Enabling privileged mode in the project configuration allows Docker commands to execute, resolving the error. Other options do not address the underlying permission issue and would not allow Docker to run.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable privileged mode in the CodeBuild project configuration.
Why this is correct
Docker requires privileged mode to run inside a container. AWS CodeBuild projects must have privileged mode enabled to build Docker images. Enabling it allows the Docker daemon to run, resolving the error. This is a common configuration for building container images in CodeBuild and is the minimal change needed to fix the issue.
- ✗
Add a pre_build phase to start the Docker daemon manually using `sudo service docker start`.
Why it's wrong here
The Docker daemon is not available because privileged mode is disabled, not because the service is stopped. Starting the daemon manually would fail without the necessary permissions. CodeBuild's managed environment does not allow starting Docker without privileged mode. The correct fix is to enable privileged mode, not to attempt manual daemon management.
- ✗
Use the `docker buildx` command instead of `docker build` to avoid needing privileged mode.
Why it's wrong here
`docker buildx` is an extended build command, but it still requires a Docker daemon and privileged mode to build images inside a container. It does not circumvent the privileged mode requirement. The error stems from the daemon not being available, so buildx would also fail. The correct solution is to enable privileged mode.
- ✗
Switch to a custom build image that includes Docker pre-installed and configured.
Why it's wrong here
The standard CodeBuild image already includes Docker, but it cannot run without privileged mode. Using a custom image would not bypass the privileged mode requirement. The issue is not the absence of Docker but the lack of permissions to run it. Therefore, changing the image does not address the root cause and adds unnecessary complexity.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.