DVA-C02 Deployment Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"codedeploy:GetDeployment",
"codedeploy:GetDeploymentGroup"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"codedeploy:CreateDeployment",
"codedeploy:RegisterApplicationRevision"
],
"Resource": "arn:aws:codedeploy:us-west-2:123456789012:deploymentgroup:MyApplication/MyDeploymentGroup"
}
]
}
```The exhibit shows an IAM policy attached to a user who needs to deploy applications using AWS CodeDeploy. The user reports that they cannot create a deployment for the MyApplication/MyDeploymentGroup. What is the most likely reason?
⚠ Common exam trap
DVA-C02 often tests the misconception that permissions on a deployment group alone are sufficient for CodeDeploy operations, when in fact permissions on both the application and deployment group resources are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not include permission on the application resource.
The IAM policy shown in the exhibit likely grants permissions on the deployment group resource (e.g., arn:aws:codedeploy:region:account:deploymentgroup:MyApplication/MyDeploymentGroup) but omits the corresponding application resource (arn:aws:codedeploy:region:account:application:MyApplication). AWS CodeDeploy requires permissions on both the application and the deployment group for operations like CreateDeployment. Without the application-level permission, the request is implicitly denied, causing the failure. Thus, the most likely reason is that the policy does not include permission on the application resource.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy restricts the user to a different deployment group.
Why it's wrong here
The policy's `Resource` element precisely defines the target as `arn:aws:codedeploy:us-east-1:123456789012:deploymentgroup/MyApplication/MyDeploymentGroup`. This explicitly grants permissions on the deployment group named 'MyApplication/MyDeploymentGroup'. Therefore, the policy restricts the user *to* this specific deployment group, not a different one, making this statement incorrect.
- ✗
The user does not have permission to call the codedeploy:CreateDeployment action.
Why it's wrong here
The policy clearly lists `codedeploy:CreateDeployment` in its `Action` element, indicating that the user *does* have permission to attempt to call this action. However, merely having the action listed is insufficient if the associated `Resource` element does not cover all required resource types for that action. The user has the permission to *call* the action, but the call will fail due to insufficient resource-level authorization.
- ✗
The user does not have permission to call codedeploy:GetDeployment and codedeploy:GetDeploymentGroup.
Why it's wrong here
The policy explicitly includes `codedeploy:GetDeployment` and `codedeploy:GetDeploymentGroup` within its `Action` element. This means the user is indeed granted permission to invoke these specific API calls. The issue is not a lack of permission for these `Get` actions themselves, but rather a potential problem with other actions or resource specifications.
- ✓
The policy does not include permission on the application resource.
Why this is correct
The `codedeploy:CreateDeployment` action requires explicit permissions on both the CodeDeploy application resource and the deployment group resource. While the policy correctly specifies the deployment group ARN (e.g., `arn:aws:codedeploy:...:deploymentgroup/MyApplication/MyDeploymentGroup`), it critically omits the necessary `application` ARN (e.g., `arn:aws:codedeploy:...:application/MyApplication`). This omission means the user lacks the required authorization on the application itself to successfully initiate a deployment.
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.