Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

Network Topology
- aws ecr get-login-passwordregion $AWS_DEFAULT_REGIONusername AWSpassword-stdin $AWS_ACCOUNT_ID.dkr.ecr.$AWS_DEFAULT_REGION.amazonaws.combuildspec.yml:version: 0.2phases:pre_build:commands:build:- docker tag myapp:latest $AWS_ACCOUNT_ID.dkr.ecr.$AWS_DEFAULT_REGION.amazonaws.com/myapp:latestpost_build:- docker push $AWS_ACCOUNT_ID.dkr.ecr.$AWS_DEFAULT_REGION.amazonaws.com/myapp:latest

Refer to the exhibit. A CodeBuild project uses this buildspec.yml to build and push a Docker image to Amazon ECR. The build fails at the pre_build phase with the error 'Error: Cannot perform an interactive login from a non TTY device'. What is the MOST likely issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CodeBuild project's IAM role does not have permission to call ecr:GetAuthorizationToken.

The error 'Cannot perform an interactive login from a non TTY device' occurs when the `docker login` command is invoked without receiving the password via stdin. In the buildspec, `aws ecr get-login-password` is used to retrieve the password and pipe it to `docker login`. If the CodeBuild project's IAM role lacks the `ecr:GetAuthorizationToken` permission, this command fails silently or returns an error, causing `docker login` to fall back to interactive mode. Since CodeBuild runs in a non‑interactive environment, it throws the TTY error. Option B is correct because the missing permission prevents the password retrieval, leading to the login failure. Options A, C, and D do not directly cause this specific error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The AWS_DEFAULT_REGION environment variable is not set in CodeBuild.

    Why it's wrong here

    CodeBuild automatically sets AWS_DEFAULT_REGION and AWS_REGION in every build container to the region where the project runs, so a missing region is virtually impossible. Even if these were absent, the AWS CLI would attempt to resolve the region from the config file or prompt "You must specify a region," and the actual failure occurs during the ECR authorization call, not before it. Therefore, this is not the root cause.

  • ✓

    The CodeBuild project's IAM role does not have permission to call ecr:GetAuthorizationToken.

    Why this is correct

    The build's `aws ecr get-login-password` command makes an ECR Authorization API call that requires the `ecr:GetAuthorizationToken` permission on the build project's service role. If that IAM policy is missing or doesn't allow the action, the CLI exits with an `AccessDeniedException` and no password is returned, causing the subsequent `docker login` to fail with invalid or empty credentials. This is the classic cause of ECR login failures in CodeBuild.

  • ✗

    The buildspec.yml is missing the 'docker login' command.

    Why it's wrong here

    The buildspec snippet actually contains the `docker login` command, piped from `aws ecr get-login-password`, so this option is factually incorrect. Even if the command were missing, the build would succeed up to that step and only then fail with a "command not found" or a missing step error, not with an authentication error. The failure here is earlier, at the point of retrieving the ECR password, not in the absence of the login invocation.

  • ✗

    The Docker daemon is not running on the CodeBuild instance.

    Why it's wrong here

    CodeBuild's managed images run the Docker daemon as a background process, and the daemon is responsible for accepting `docker login` and build commands; if it were down, the error would be "Cannot connect to the Docker daemon at unix:///var/run/docker.sock" rather than an ECR authorization failure. The command `docker login` with `--password-stdin` does not require the daemon to be running to fail; it fails because the password piped to it was generated by an unauthenticated call to ECR. Hence, the daemon is not the issue.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.