DOP-C02 SDLC Automation Practice Question
A team wants to run a CodeBuild project that builds a container image and pushes it to Amazon ECR, but the build currently fails with an access denied error when calling ecr:InitiateLayerUpload. The CodeBuild project uses a service role and runs in a VPC. Which TWO actions should the engineer take to resolve the error while keeping the build functional? (Choose two.)
⚠ Common exam trap
The trap here is assuming privileged mode or static credentials fix an access denied error, when the error is about missing IAM permissions and, for VPC builds, missing network paths to ECR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to the CodeBuild service role granting the required Amazon ECR push actions on the target repository.
The failure is an authorization and connectivity issue, not a Docker capability issue. Adding the required ECR push permissions to the CodeBuild service role authorizes the API calls, and ensuring the VPC can reach ECR endpoints allows the push to complete. Together these address both the permission and network dimensions of the error without introducing static credentials or unnecessary privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the CodeBuild project's privileged mode to true so the Docker daemon can authenticate to Amazon ECR.
Why it's wrong here
Privileged mode allows the build container to run a Docker daemon, which is necessary for building images, but it does not grant AWS API permissions. Enabling it when the image already builds does not fix an ecr:InitiateLayerUpload access denied error and can widen the container's capabilities unnecessarily.
- ✗
Change the buildspec to use the AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables stored in plaintext.
Why it's wrong here
Hardcoding long-lived credentials in plaintext exposes them to anyone who can read the build configuration and does not address the underlying authorization model. CodeBuild already provides credentials through its service role, so adding static keys replaces a secure mechanism with a weaker one and still may lack the needed ECR permissions.
- ✓
Attach an IAM policy to the CodeBuild service role granting the required Amazon ECR push actions on the target repository.
Why this is correct
The access denied error indicates the build's AWS credentials lack permission for ECR push operations. Granting ecr:InitiateLayerUpload along with the related push actions such as ecr:PutImage and ecr:UploadLayerPart on the specific repository authorizes the docker push and directly resolves the failure.
- ✗
Disable the CodeBuild service role and switch the project to use an IAM user's access keys for authentication.
Why it's wrong here
Replacing the service role with an IAM user's keys moves the project to long-lived credentials that must be rotated manually and are harder to scope. It does not inherently grant ECR push permissions unless those permissions are attached, and it weakens the security posture compared with a properly scoped service role.
- ✓
If the build runs in a VPC, ensure a NAT gateway or VPC endpoint allows connectivity to Amazon ECR and its dependent services.
Why this is correct
A CodeBuild project in a private VPC needs outbound connectivity to reach ECR endpoints. Without a NAT gateway or an interface VPC endpoint for ecr.api, ecr.dkr, and the S3 gateway endpoint for layer storage, the docker push cannot reach ECR, which manifests as connection or access failures during image upload.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.