DVA-C02 Development with AWS Services Practice Question
A developer is building a CI/CD pipeline using AWS CodePipeline. The pipeline has a source stage from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The developer wants to ensure that a manual approval step is required before deploying to production. Which THREE components must be configured? (Choose THREE.)
⚠ Common exam trap
The trap here is that candidates might think a custom Lambda function or CloudWatch Events is needed to implement the approval logic, but CodePipeline provides a native approval action that handles both the pause and notification via SNS, requiring only the IAM permission to submit the result.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up an Amazon SNS topic to notify approvers of pending approval.
Amazon SNS is used to send notifications to approvers when a manual approval action is pending in the pipeline. The approval action in CodePipeline can be configured with an SNS topic ARN, and when the pipeline reaches that stage, it publishes a notification to the topic, alerting approvers to review and approve or reject the deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an AWS Lambda function to process approval logic.
Why it's wrong here
The AWS CodePipeline manual approval action is a built-in feature that inherently handles the logic for pausing the pipeline and awaiting a decision. It does not require an external AWS Lambda function to process or implement the core approval logic itself. Lambda functions are typically employed for custom actions, complex business rule evaluations *after* an approval, or for highly customized notification mechanisms, but not for the fundamental approval decision processing within CodePipeline.
- ✓
Set up an Amazon SNS topic to notify approvers of pending approval.
Why this is correct
Setting up an Amazon SNS topic is a fundamental step when configuring a manual approval action in AWS CodePipeline. This SNS topic serves as the primary mechanism for automatically notifying designated approvers, typically via email or other subscribed endpoints, that a pipeline execution has reached a manual approval gate and is awaiting their intervention. Without an associated SNS topic, approvers would lack timely, automated alerts regarding pending approvals, potentially causing significant delays in the deployment process.
- ✓
Add an approval action in the pipeline before the deploy stage.
Why this is correct
To effectively implement a manual approval gate within an AWS CodePipeline, a developer must explicitly add an "Approval" action type into the pipeline's stage definition. Strategically placing this action before critical stages, such as a production deploy stage, ensures that the pipeline execution pauses at that point. This provides a mandatory human review and approval checkpoint, preventing automated progression until an authorized individual has manually validated the changes.
- ✓
Attach an IAM policy to the approver group that allows codepipeline:PutApprovalResult.
Why this is correct
For any IAM user or role to successfully interact with and submit a decision for a pending manual approval action in AWS CodePipeline, they must be granted the `codepipeline:PutApprovalResult` permission. This specific IAM action is crucial as it authorizes the principal to either approve or reject the pipeline's progression. Without this permission, even if notified, approvers would be unable to submit their decision, effectively blocking the pipeline.
- ✗
Configure Amazon CloudWatch Events to trigger the approval step.
Why it's wrong here
Amazon CloudWatch Events (now largely superseded by Amazon EventBridge) is primarily designed to react to state changes in AWS services or on a schedule, triggering other services or custom actions. However, a manual approval step in CodePipeline is an intrinsic action within the pipeline's workflow that pauses execution until a decision is made. It is not triggered by external CloudWatch Events; rather, the pipeline execution simply reaches this predefined action and waits for input.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.