DVA-C02 Development with AWS Services Practice Question
A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that pulls code from an Amazon S3 bucket. Which THREE steps should the developer take to ensure that only approved changes are deployed to production?
⚠ Common exam trap
Candidates often confuse security controls (like encryption or cross-account access) with governance controls (like approval workflows), leading them to select options that protect data but do not enforce change approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation change sets to review changes
AWS CloudFormation change sets allow you to preview how proposed changes to a stack will impact existing resources before you execute them. By reviewing the change set, you can verify that only approved modifications (e.g., infrastructure updates) are applied, providing a safety check before deployment to production. This step ensures that unapproved or unintended changes are caught early in the pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS CloudFormation change sets to review changes
Why this is correct
CloudFormation change sets provide a summary of proposed changes to your AWS resources before they are actually implemented. Integrating change sets into a CodePipeline stage allows developers to review the exact modifications (e.g., resource additions, deletions, or property updates) that a new CloudFormation template would make to the existing stack. This critical review step helps prevent unintended resource modifications or accidental deletions in production environments, ensuring controlled and predictable infrastructure updates.
- ✓
Enable versioning on the S3 bucket
Why this is correct
Enabling versioning on the Amazon S3 bucket used to store build artifacts, source code, or deployment packages within a CodePipeline ensures that every iteration of an object is preserved. If a deployment introduces issues, this versioning allows for a straightforward rollback to a previous, known-good version of the artifact by simply redeploying an older object version from the bucket. This capability is vital for maintaining system stability and quickly recovering from faulty deployments without data loss.
- ✗
Configure cross-account access for the pipeline
Why it's wrong here
Configuring cross-account access for a CodePipeline primarily facilitates the deployment of resources into different AWS accounts (e.g., dev, test, prod) from a central pipeline account. This involves setting up IAM roles with appropriate trust policies and permissions to allow the pipeline to assume roles in target accounts. While essential for multi-account strategies, cross-account access itself does not inherently provide a mechanism for human review or approval of changes before deployment; it's about access, not gating.
- ✓
Add a manual approval step before the production deployment
Why this is correct
Integrating a manual approval action into an AWS CodePipeline stage, particularly before production deployment, explicitly pauses the pipeline's execution. This pause requires a designated IAM user or role to manually approve or reject the pending deployment, often after reviewing test results or proposed changes. This critical human gate ensures that all necessary checks, compliance requirements, or business decisions are met before potentially impactful changes are released to end-users in a live environment.
- ✗
Encrypt the S3 bucket with AWS KMS
Why it's wrong here
Encrypting the Amazon S3 bucket used by CodePipeline with AWS Key Management Service (KMS) ensures that all stored artifacts, such as source code, build outputs, and deployment packages, are protected at rest. This is a fundamental security best practice for data confidentiality and compliance. However, encryption is a data protection mechanism and does not provide any functionality for reviewing proposed infrastructure changes, enabling rollbacks, or implementing human approval gates within the CI/CD workflow.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.