DVA-C02 Deployment Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"codebuild:StartBuild",
"codebuild:BatchGetBuilds"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"codepipeline:StartPipelineExecution",
"codepipeline:GetPipelineExecution"
],
"Resource": "arn:aws:codepipeline:us-east-1:123456789012:MyPipeline"
}
]
}Refer to the exhibit. A developer created this IAM policy to allow a CI/CD service to trigger CodePipeline and CodeBuild. However, the pipeline fails with an 'AccessDenied' error when trying to start the CodeBuild project. What is the likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy is attached to the developer's IAM user instead of the CodePipeline service role.
The policy is correctly defined to allow 'codebuild:StartBuild' on all resources, so options B and C are incorrect. Option A is incorrect because using 'Deny' would block the action entirely. The actual cause is that the policy is attached to the developer's IAM user, but CodePipeline requires the permissions to be attached to its service role. When CodePipeline tries to start the CodeBuild project on behalf of the pipeline, it uses the service role, not the developer's user. Therefore, the policy must be attached to the CodePipeline service role to grant the necessary permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy should use 'Effect': 'Deny' for the CodeBuild actions.
Why it's wrong here
The purpose of this IAM policy is to grant necessary permissions for CodePipeline to interact with CodeBuild. Using 'Effect': 'Deny' for CodeBuild actions would explicitly prevent CodePipeline from performing operations like starting builds or retrieving build statuses. A Deny statement always overrides Allow statements, meaning CodePipeline would encounter access denied errors, completely preventing the pipeline from functioning as intended.
- ✗
The policy does not include 'codebuild:StartBuild' for the specific CodeBuild project ARN.
Why it's wrong here
The policy statement already includes 'codebuild:StartBuild' with a Resource value of '*'. This wildcard resource specification grants permission to initiate builds on any CodeBuild project within the AWS account. Therefore, the policy does not need to include a specific CodeBuild project ARN, as the existing wildcard already covers all projects, making this statement incorrect.
- ✗
The policy must include 'codebuild:BatchGetBuilds' for the specific project.
Why it's wrong here
The provided policy already contains a statement that explicitly grants 'codebuild:BatchGetBuilds' permission. This permission is applied to Resource: '*', meaning it covers all CodeBuild projects. Therefore, the assertion that the policy must include codebuild:BatchGetBuilds for a specific project is inaccurate, as the broader permission is already present.
- ✓
The policy is attached to the developer's IAM user instead of the CodePipeline service role.
Why this is correct
AWS CodePipeline, like many other AWS services, operates by assuming an IAM service role to perform actions on its behalf. For CodePipeline to interact with CodeBuild, the necessary permissions (e.g., codebuild:StartBuild, codebuild:BatchGetBuilds) must be attached to CodePipeline's service role. Attaching the policy to a developer's IAM user only grants the user these permissions, not the CodePipeline service itself, leading to permission failures during pipeline execution.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.