DVA-C02 Development with AWS Services Practice Question
An organization uses AWS CodeBuild to run tests for a Node.js application. The build environment is Linux. The buildspec.yml includes a pre_build phase that runs 'npm install'. Occasionally, the build fails with an error 'npm ERR! code EINTEGRITY'. The developer wants to resolve this issue without compromising security. Which action should be taken?
⚠ Common exam trap
DVA-C02 often tests the misconception that EINTEGRITY errors are network-related and can be fixed by changing registry protocols or offline flags, when the actual cause is local cache corruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'npm cache verify' to the pre_build phase before 'npm install'.
The EINTEGRITY error occurs when npm's local cache contains corrupted or mismatched package data, causing integrity checks to fail. Running 'npm cache verify' in the pre_build phase validates the cache, removes corrupted entries, and garbage collects unnecessary data, ensuring subsequent 'npm install' operations use a clean cache. This resolves the issue without disabling security features like integrity checking or switching to insecure HTTP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a separate CodeBuild project to run npm install.
Why it's wrong here
Creating a separate CodeBuild project does not resolve an `npm` cache integrity issue. CodeBuild environments are typically ephemeral, and while CodeBuild offers caching mechanisms, the `npm` cache itself is usually stored within the build environment's local filesystem. A new project would either start with a fresh, empty `npm` cache (which might temporarily resolve the issue but doesn't fix the root cause if it's a recurring problem) or, if CodeBuild's own caching is misconfigured, could still reuse a corrupted `npm` cache. The problem lies with the cache's content, not the project's existence.
- ✓
Add 'npm cache verify' to the pre_build phase before 'npm install'.
Why this is correct
Adding 'npm cache verify' to the `pre_build` phase before 'npm install' is the correct solution because it directly addresses the cause of an 'EINTEGRITY' error. This command systematically checks the integrity of all cached packages, identifying and repairing any corrupted or incomplete entries. By ensuring the npm cache is clean and valid, subsequent 'npm install' commands will operate with correct package data, resolving the integrity mismatch without compromising security or requiring a full cache clear.
- ✗
Add 'npm config set registry http://registry.npmjs.org/' to use HTTP.
Why it's wrong here
This approach is fundamentally flawed because an 'EINTEGRITY' error indicates a hash mismatch, meaning the downloaded package does not match its expected integrity checksum. Switching to an HTTP registry disables crucial HTTPS integrity checks, which are designed to prevent tampering and ensure package authenticity. While it might bypass the error by not performing the check, it severely compromises the security of your build by allowing potentially corrupted or malicious packages to be installed without detection, rather than fixing the underlying data integrity issue.
- ✗
Use 'npm install --prefer-offline' to avoid fetching from registry.
Why it's wrong here
Using 'npm install --prefer-offline' instructs npm to prioritize packages from its local cache and avoid network requests if possible. However, if the 'EINTEGRITY' error stems from corruption within that local cache, this command will simply attempt to use the already corrupted data, leading to the same integrity error. It does not validate or repair the cache contents; it only changes the fetching strategy, thus failing to address the root cause of the integrity problem.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.