Courseiva
Deployment →hardMultiple Choice

DVA-C02 Deployment Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "codebuild:StartBuild",
        "codebuild:BatchGetBuilds"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "codepipeline:StartPipelineExecution",
        "codepipeline:GetPipelineExecution"
      ],
      "Resource": "arn:aws:codepipeline:us-east-1:123456789012:MyPipeline"
    }
  ]
}

Refer to the exhibit. A developer created this IAM policy to allow a CI/CD service to trigger CodePipeline and CodeBuild. However, the pipeline fails with an 'AccessDenied' error when trying to start the CodeBuild project. What is the likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy is attached to the developer's IAM user instead of the CodePipeline service role.

The policy is correctly defined to allow 'codebuild:StartBuild' on all resources, so options B and C are incorrect. Option A is incorrect because using 'Deny' would block the action entirely. The actual cause is that the policy is attached to the developer's IAM user, but CodePipeline requires the permissions to be attached to its service role. When CodePipeline tries to start the CodeBuild project on behalf of the pipeline, it uses the service role, not the developer's user. Therefore, the policy must be attached to the CodePipeline service role to grant the necessary permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy should use 'Effect': 'Deny' for the CodeBuild actions.

    Why it's wrong here

    The purpose of this IAM policy is to grant necessary permissions for CodePipeline to interact with CodeBuild. Using 'Effect': 'Deny' for CodeBuild actions would explicitly prevent CodePipeline from performing operations like starting builds or retrieving build statuses. A Deny statement always overrides Allow statements, meaning CodePipeline would encounter access denied errors, completely preventing the pipeline from functioning as intended.

  • ✗

    The policy does not include 'codebuild:StartBuild' for the specific CodeBuild project ARN.

    Why it's wrong here

    The policy statement already includes 'codebuild:StartBuild' with a Resource value of '*'. This wildcard resource specification grants permission to initiate builds on any CodeBuild project within the AWS account. Therefore, the policy does not need to include a specific CodeBuild project ARN, as the existing wildcard already covers all projects, making this statement incorrect.

  • ✗

    The policy must include 'codebuild:BatchGetBuilds' for the specific project.

    Why it's wrong here

    The provided policy already contains a statement that explicitly grants 'codebuild:BatchGetBuilds' permission. This permission is applied to Resource: '*', meaning it covers all CodeBuild projects. Therefore, the assertion that the policy must include codebuild:BatchGetBuilds for a specific project is inaccurate, as the broader permission is already present.

  • ✓

    The policy is attached to the developer's IAM user instead of the CodePipeline service role.

    Why this is correct

    AWS CodePipeline, like many other AWS services, operates by assuming an IAM service role to perform actions on its behalf. For CodePipeline to interact with CodeBuild, the necessary permissions (e.g., codebuild:StartBuild, codebuild:BatchGetBuilds) must be attached to CodePipeline's service role. Attaching the policy to a developer's IAM user only grants the user these permissions, not the CodePipeline service itself, leading to permission failures during pipeline execution.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.