DVA-C02 Security Practice Question
A developer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a Lambda function. Which THREE practices should be followed to ensure security?
⚠ Common exam trap
Many candidates confuse CloudFront's artifact distribution capability with S3's role in CodePipeline, or assume TLS encryption is an optional security practice rather than a default AWS behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use IAM roles for pipeline actions instead of access keys.
IAM roles provide temporary credentials for AWS services, eliminating the need to manage long-term access keys. CodePipeline can assume an IAM role to perform actions like deploying a Lambda function, which reduces the risk of credential leakage. This follows the principle of least privilege and is a security best practice for automated pipelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use IAM roles for pipeline actions instead of access keys.
Why this is correct
IAM roles provide temporary, short-lived credentials that are automatically rotated by AWS, significantly reducing the risk associated with long-lived access keys. When an AWS service like CodeBuild or CodeDeploy assumes an IAM role, it receives a temporary security token, eliminating the need to embed static credentials directly into pipeline configurations or source code. This aligns with the principle of least privilege and enhances security posture by preventing credential leakage and simplifying credential management.
- ✓
Scan code dependencies for known vulnerabilities.
Why this is correct
Scanning code dependencies for known vulnerabilities, often referred to as Software Composition Analysis (SCA), is a critical "shift left" security practice. This involves analyzing third-party libraries and packages used in the application for publicly disclosed Common Vulnerabilities and Exposures (CVEs). Integrating tools like Amazon Inspector or other SAST/DAST solutions into the CI/CD pipeline helps identify and remediate security flaws early, preventing vulnerable code from reaching production environments and reducing potential attack surfaces.
- ✗
Use CloudFront to distribute pipeline artifacts.
Why it's wrong here
CloudFront is a Content Delivery Network (CDN) designed to cache and distribute static and dynamic web content globally with low latency. Its primary purpose is to serve end-users efficiently, not to store or distribute internal pipeline artifacts between build stages. Storing pipeline artifacts in CloudFront offers no security or performance benefits for internal CI/CD processes, as artifacts are typically consumed by other AWS services within the same region, making Amazon S3 the appropriate and cost-effective solution for secure artifact storage.
- ✓
Store database credentials in AWS Secrets Manager and retrieve them during deployment.
Why this is correct
AWS Secrets Manager provides a dedicated, secure service for storing, managing, and automatically rotating sensitive information like database credentials, API keys, and other secrets. By retrieving credentials programmatically during deployment, applications avoid hardcoding secrets in source code or configuration files, significantly reducing the risk of exposure. Secrets Manager encrypts secrets at rest and in transit, offers fine-grained access control through IAM, and integrates with other AWS services to enhance overall security and compliance.
- ✗
Encrypt artifacts in transit using TLS.
Why it's wrong here
Encrypting artifacts in transit using TLS (Transport Layer Security) is a fundamental security measure that AWS services inherently implement for all data transfers over public networks. When interacting with AWS APIs or transferring data between services like S3, CodeBuild, or CodeDeploy, TLS/SSL is automatically used to establish secure, encrypted communication channels. Therefore, explicitly stating "encrypt artifacts in transit using TLS" is redundant as it's a default, built-in security feature rather than an additional best practice a developer needs to implement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.