Courseiva
Incident and Event Response →mediumMultiple Choice

DOP-C02 Incident and Event Response Practice Question

An application running on Amazon ECS Fargate is experiencing intermittent 'CannotPullContainerError' errors. The task definition references a Docker image in a private Amazon ECR repository. The task execution role has the 'AmazonECSTaskExecutionRolePolicy' policy attached. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Fargate task is in a private subnet without a NAT gateway or VPC endpoint

The 'CannotPullContainerError' occurs when the ECS task cannot retrieve the container image from ECR. Since the task execution role has the 'AmazonECSTaskExecutionRolePolicy' attached, which includes the necessary permissions (ecr:GetAuthorizationToken, ecr:BatchCheckLayerAvailability, ecr:BatchGetImage, ecr:GetDownloadUrlForLayer), the issue is not permissions. The most likely cause is that the Fargate task is running in a private subnet that lacks a route to the internet (via NAT gateway) or a VPC endpoint for ECR. Without either, the task cannot reach the ECR API to pull the image. Option A is correct. Option B is wrong because the policy provides sufficient permissions. Option C is irrelevant; Auto Scaling does not affect image pulling. Option D is less likely because ECR repositories are typically in the same region, and cross-region pulls would still be possible with proper permissions and networking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Fargate task is in a private subnet without a NAT gateway or VPC endpoint

    Why this is correct

    Fargate tasks provisioned in a private subnet have no route to the internet unless a NAT gateway is configured in a public subnet. Because ECR's API and Docker Hub need outbound HTTPS access, and image layers are fetched from Amazon S3, the task's image pull fails without a NAT gateway or VPC endpoints for ECR (both API and DKR) and S3. This manifests as a 'CannotPullContainerError' or 'ResourceInitializationError' in the task's stopped reason. Adding a NAT gateway or the appropriate VPC endpoints resolves the issue.

  • ✗

    The task execution role does not have sufficient permissions

    Why it's wrong here

    The task execution role grants permissions for ECS to pull container images, retrieve secrets, and access CloudWatch logs. If the role lacked the required actions like ecr:GetAuthorizationToken, ecr:BatchGetImage, and ecr:GetDownloadUrlForLayer, ECS would report an AccessDenied error when attempting the pull. However, the policy in question already includes the necessary permissions, so the role is not the bottleneck. An authorization failure produces a different error message than the network timeout seen in this problem.

  • ✗

    The ECS service is not configured with Auto Scaling

    Why it's wrong here

    Auto Scaling for an ECS service adjusts the desired task count based on CloudWatch alarms or target tracking, but it has no bearing on the ability of an individual task to pull its container image. When a new task is launched, the image pull process depends solely on network access and the execution role's permissions, not on the scaling configuration. Even without Auto Scaling, a task at the desired count will still attempt to start and pull the image. Therefore, this option explains none of the observed startup failures.

  • ✗

    The ECR repository is not in the same region as the ECS cluster

    Why it's wrong here

    ECR is a regional service, and cross-region pulls are technically supported if the task execution role is granted permissions for the repository in the remote region and the network path allows outbound access. A region mismatch would typically produce an authorization error because the registry endpoint differs, rather than a network connectivity failure. Since the described symptom is a network-level timeout, the region difference is not the root cause. Additional cross-region permissions might be needed, but the problem persists even in the same-region scenario, so this is incorrect.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.