Courseiva

DVA-C02 Development with AWS Services Practice Question

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that pulls code from an Amazon S3 bucket. Which THREE steps should the developer take to ensure that only approved changes are deployed to production?

⚠ Common exam trap

Candidates often confuse security controls (like encryption or cross-account access) with governance controls (like approval workflows), leading them to select options that protect data but do not enforce change approval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudFormation change sets to review changes

AWS CloudFormation change sets allow you to preview how proposed changes to a stack will impact existing resources before you execute them. By reviewing the change set, you can verify that only approved modifications (e.g., infrastructure updates) are applied, providing a safety check before deployment to production. This step ensures that unapproved or unintended changes are caught early in the pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS CloudFormation change sets to review changes

    Why this is correct

    CloudFormation change sets provide a summary of proposed changes to your AWS resources before they are actually implemented. Integrating change sets into a CodePipeline stage allows developers to review the exact modifications (e.g., resource additions, deletions, or property updates) that a new CloudFormation template would make to the existing stack. This critical review step helps prevent unintended resource modifications or accidental deletions in production environments, ensuring controlled and predictable infrastructure updates.

  • ✓

    Enable versioning on the S3 bucket

    Why this is correct

    Enabling versioning on the Amazon S3 bucket used to store build artifacts, source code, or deployment packages within a CodePipeline ensures that every iteration of an object is preserved. If a deployment introduces issues, this versioning allows for a straightforward rollback to a previous, known-good version of the artifact by simply redeploying an older object version from the bucket. This capability is vital for maintaining system stability and quickly recovering from faulty deployments without data loss.

  • ✗

    Configure cross-account access for the pipeline

    Why it's wrong here

    Configuring cross-account access for a CodePipeline primarily facilitates the deployment of resources into different AWS accounts (e.g., dev, test, prod) from a central pipeline account. This involves setting up IAM roles with appropriate trust policies and permissions to allow the pipeline to assume roles in target accounts. While essential for multi-account strategies, cross-account access itself does not inherently provide a mechanism for human review or approval of changes before deployment; it's about access, not gating.

  • ✓

    Add a manual approval step before the production deployment

    Why this is correct

    Integrating a manual approval action into an AWS CodePipeline stage, particularly before production deployment, explicitly pauses the pipeline's execution. This pause requires a designated IAM user or role to manually approve or reject the pending deployment, often after reviewing test results or proposed changes. This critical human gate ensures that all necessary checks, compliance requirements, or business decisions are met before potentially impactful changes are released to end-users in a live environment.

  • ✗

    Encrypt the S3 bucket with AWS KMS

    Why it's wrong here

    Encrypting the Amazon S3 bucket used by CodePipeline with AWS Key Management Service (KMS) ensures that all stored artifacts, such as source code, build outputs, and deployment packages, are protected at rest. This is a fundamental security best practice for data confidentiality and compliance. However, encryption is a data protection mechanism and does not provide any functionality for reviewing proposed infrastructure changes, enabling rollbacks, or implementing human approval gates within the CI/CD workflow.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.