DVA-C02 Deployment Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"elasticbeanstalk:DescribeEnvironmentResources",
"elasticbeanstalk:UpdateEnvironment"
],
"Resource": "arn:aws:elasticbeanstalk:us-east-1:123456789012:environment/MyApp/MyEnv"
},
{
"Effect": "Deny",
"Action": "elasticbeanstalk:DeleteEnvironment",
"Resource": "*"
}
]
}
```A developer is troubleshooting a deployment failure in AWS CodePipeline. The deploy stage uses the above IAM policy for the service role. The pipeline fails when trying to update the Elastic Beanstalk environment. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy restricts the UpdateEnvironment action to a specific environment ARN, but the pipeline is updating a different environment.
The most likely cause is option A: the policy restricts the UpdateEnvironment action to a specific environment ARN, but the pipeline is updating a different environment. In Elastic Beanstalk, elasticbeanstalk:UpdateEnvironment must be allowed on the exact environment ARN being updated; if the Resource element names a different environment, the API call is denied and the deploy stage fails. Option B is not the issue because DescribeEnvironmentResources is a read-only action and is not required to perform the environment update. Option C is too broad and inaccurate, since the policy does not deny all actions on the environment. Option D is also incorrect because DeleteEnvironment is not needed to update an existing Elastic Beanstalk environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy restricts the UpdateEnvironment action to a specific environment ARN, but the pipeline is updating a different environment.
Why this is correct
When an IAM policy scopes elasticbeanstalk:UpdateEnvironment to a specific environment ARN in its Resource element, any UpdateEnvironment call targeting a different environment ARN is evaluated against no matching Allow statement and is implicitly denied, which precisely matches a pipeline that fails only when updating an environment other than the one named in the policy.
- ✗
The policy does not allow DescribeEnvironmentResources, which is required for the deployment.
Why it's wrong here
The scenario's policy does grant DescribeEnvironmentResources, so a missing permission for that specific read-only action is not the cause — CodePipeline's Elastic Beanstalk deploy action relies primarily on UpdateEnvironment and related describe calls succeeding, and this action was not the one restricted in the given policy.
- ✗
The policy denies all actions on the environment, preventing the update.
Why it's wrong here
The policy as described does not include a blanket deny on all actions against the environment; only a narrower, specific restriction is in place (the ARN-scoped Allow condition), so characterizing it as an all-actions deny mischaracterizes the actual structure and effect of the policy shown in the exhibit.
- ✗
The policy denies DeleteEnvironment, which is required for the update.
Why it's wrong here
elasticbeanstalk:DeleteEnvironment is an action used to terminate an environment entirely and plays no role in the UpdateEnvironment API call that CodePipeline's deploy stage invokes to roll out a new application version, so a deny on DeleteEnvironment would not cause an update operation to fail.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.