DOP-C02 Incident and Event Response Practice Question
An application running on Amazon ECS Fargate is experiencing intermittent 'CannotPullContainerError' errors. The task definition references a Docker image in a private Amazon ECR repository. The task execution role has the 'AmazonECSTaskExecutionRolePolicy' policy attached. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Fargate task is in a private subnet without a NAT gateway or VPC endpoint
The 'CannotPullContainerError' occurs when the ECS task cannot retrieve the container image from ECR. Since the task execution role has the 'AmazonECSTaskExecutionRolePolicy' attached, which includes the necessary permissions (ecr:GetAuthorizationToken, ecr:BatchCheckLayerAvailability, ecr:BatchGetImage, ecr:GetDownloadUrlForLayer), the issue is not permissions. The most likely cause is that the Fargate task is running in a private subnet that lacks a route to the internet (via NAT gateway) or a VPC endpoint for ECR. Without either, the task cannot reach the ECR API to pull the image. Option A is correct. Option B is wrong because the policy provides sufficient permissions. Option C is irrelevant; Auto Scaling does not affect image pulling. Option D is less likely because ECR repositories are typically in the same region, and cross-region pulls would still be possible with proper permissions and networking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Fargate task is in a private subnet without a NAT gateway or VPC endpoint
Why this is correct
Fargate tasks provisioned in a private subnet have no route to the internet unless a NAT gateway is configured in a public subnet. Because ECR's API and Docker Hub need outbound HTTPS access, and image layers are fetched from Amazon S3, the task's image pull fails without a NAT gateway or VPC endpoints for ECR (both API and DKR) and S3. This manifests as a 'CannotPullContainerError' or 'ResourceInitializationError' in the task's stopped reason. Adding a NAT gateway or the appropriate VPC endpoints resolves the issue.
- ✗
The task execution role does not have sufficient permissions
Why it's wrong here
The task execution role grants permissions for ECS to pull container images, retrieve secrets, and access CloudWatch logs. If the role lacked the required actions like ecr:GetAuthorizationToken, ecr:BatchGetImage, and ecr:GetDownloadUrlForLayer, ECS would report an AccessDenied error when attempting the pull. However, the policy in question already includes the necessary permissions, so the role is not the bottleneck. An authorization failure produces a different error message than the network timeout seen in this problem.
- ✗
The ECS service is not configured with Auto Scaling
Why it's wrong here
Auto Scaling for an ECS service adjusts the desired task count based on CloudWatch alarms or target tracking, but it has no bearing on the ability of an individual task to pull its container image. When a new task is launched, the image pull process depends solely on network access and the execution role's permissions, not on the scaling configuration. Even without Auto Scaling, a task at the desired count will still attempt to start and pull the image. Therefore, this option explains none of the observed startup failures.
- ✗
The ECR repository is not in the same region as the ECS cluster
Why it's wrong here
ECR is a regional service, and cross-region pulls are technically supported if the task execution role is granted permissions for the repository in the remote region and the network path allows outbound access. A region mismatch would typically produce an authorization error because the registry endpoint differs, rather than a network connectivity failure. Since the described symptom is a network-level timeout, the region difference is not the root cause. Additional cross-region permissions might be needed, but the problem persists even in the same-region scenario, so this is incorrect.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.