DVA-C02 Troubleshooting and Optimization Practice Question
A developer is using AWS CodePipeline to deploy a web application. The pipeline has a source stage from GitHub and a deploy stage to Elastic Beanstalk. The deploy stage fails with the error 'The S3 bucket does not allow access to the artifact'. Which THREE actions could resolve this issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy that grants the pipeline's service role access to the artifact bucket.
The deploy stage fails because the CodePipeline service role cannot access the artifact S3 bucket. To resolve this, you can: (1) Attach a bucket policy that grants the pipeline's service role access to the bucket (Option B). (2) Ensure the pipeline's IAM role has the necessary S3 permissions: s3:GetObject and s3:PutObject on the artifact bucket (Option C). (3) If the artifact bucket uses AWS KMS encryption, the pipeline role also needs kms:Decrypt permission to read the encrypted artifacts (Option D). Option A is not a direct fix — specifying a different bucket may avoid the issue but does not address the access problem with the current bucket. Option E is irrelevant because bucket versioning does not affect access permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Specify a different artifact bucket in the pipeline configuration.
Why it's wrong here
Specifying a different artifact bucket in the pipeline configuration is a workaround that does not address the root cause of an access issue with the original bucket. Unless the new bucket is already correctly configured with the necessary permissions for the CodePipeline's IAM role, it would likely encounter the same access denied problems. This action avoids the problem rather than solving the underlying security misconfiguration.
- ✓
Add a bucket policy that grants the pipeline's service role access to the artifact bucket.
Why this is correct
An S3 bucket policy is a resource-based policy attached directly to the S3 bucket, allowing you to grant permissions to AWS accounts, IAM users, or IAM roles, even across different AWS accounts. Adding a bucket policy that explicitly grants `s3:GetObject` and `s3:PutObject` (and potentially `s3:ListBucket`) permissions to the CodePipeline's service role ensures the pipeline has the necessary access to store and retrieve artifacts, complementing or overriding identity-based policies.
- ✓
Ensure the pipeline's IAM role has s3:GetObject and s3:PutObject permissions on the artifact bucket.
Why this is correct
The AWS CodePipeline service role requires explicit permissions to interact with the S3 artifact bucket. Specifically, `s3:GetObject` is needed to retrieve input artifacts for pipeline stages, and `s3:PutObject` is required to store output artifacts generated by stages (e.g., build outputs, deployment packages). Without these permissions, the pipeline cannot read from or write to its designated artifact storage, leading to failures.
- ✓
If the artifact bucket is encrypted with AWS KMS, ensure the pipeline role has kms:Decrypt permission.
Why this is correct
If the S3 artifact bucket is encrypted using AWS Key Management Service (AWS KMS), the CodePipeline's IAM role must have permission to use the specific KMS key for decryption. The `kms:Decrypt` permission on the KMS key is essential for the pipeline to access and process encrypted artifacts. Without this, the pipeline stages will fail when attempting to read encrypted objects from the artifact bucket.
- ✗
Enable versioning on the artifact bucket.
Why it's wrong here
Enabling versioning on an S3 bucket is a data protection feature that preserves multiple versions of an object, allowing for recovery from accidental deletions or overwrites. However, S3 versioning does not grant or revoke access permissions to the bucket or its objects. Therefore, enabling it would not resolve any underlying access denied errors for the CodePipeline's IAM role.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.