DOP-C02 SDLC Automation Practice Question
A startup is using AWS CodeBuild to build and test their application. The build process takes about 10 minutes. Recently, they noticed that some builds are failing randomly with the error 'Could not download dependencies'. The build environment uses a custom Docker image stored in Amazon ECR. The team suspects that the issue is due to network connectivity problems when pulling the Docker image or dependencies from the internet. They want to ensure reliable and faster builds. Which solution should they implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure CodeBuild to use a VPC with a NAT gateway
To improve reliability and speed, configure CodeBuild to use a VPC with a NAT gateway. This provides consistent internet access for pulling dependencies and Docker images, and allows using VPC endpoints for Amazon ECR, reducing network failures. Option D is correct. Option A (using a public Docker Hub) does not address the underlying network issues and may introduce additional points of failure. Option B (increasing build timeout) does not fix the root cause of connectivity problems. Option C (using a larger compute type) does not resolve network connectivity issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Switch to using a public Docker image from Docker Hub
Why it's wrong here
Switching to a public Docker image from Docker Hub does not address the root cause of the build failure. The CodeBuild environment's inability to reach external endpoints remains identical whether you pull from Amazon ECR or Docker Hub, because both require reliable outbound internet connectivity. Moreover, public images introduce supply-chain and security risks, as they are not curated or version-controlled by your organization, making this an inferior and ineffective fix.
- ✗
Increase the build timeout in CodeBuild project settings
Why it's wrong here
Increasing the build timeout in CodeBuild project settings only extends the maximum duration before the build is forcibly stopped. Network failures such as DNS resolution errors, connection resets, or 503 responses from dependency repositories happen immediately and do not improve with additional time. If the build cannot reach the internet, it will fail consistently regardless of the timeout value, and a longer timeout simply wastes compute cost while the failed build retries or hangs.
- ✗
Use a larger compute type for the CodeBuild project
Why it's wrong here
Selecting a larger compute type for the CodeBuild project increases vCPU and memory resources, but the network stack, routing tables, and egress path remain unchanged. The default managed CodeBuild environment still suffers from the same lack of controlled outbound connectivity, so dependency download and image pulls continue to fail. Compute size has no bearing on the ability to reach external hosts; network misconfigurations require network-level fixes, not more processing power.
- ✓
Configure CodeBuild to use a VPC with a NAT gateway
Why this is correct
Configuring CodeBuild to use a VPC with a NAT gateway is the correct solution because it provides a deterministic, controlled egress path for outbound internet traffic. By running the build in private subnets behind a NAT gateway that routes via an Internet Gateway, the build environment can reliably pull layers from Docker Hub, install packages, and access private VPC resources. This overrides the default AWS-managed network's unpredictable connectivity and gives you proper security group and routing control, making the build network behavior explicit and dependable.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.