DOP-C02 SDLC Automation Practice Question
A company is designing a CI/CD pipeline for a serverless application using AWS CodePipeline. Which TWO actions are valid ways to deploy an AWS Lambda function?
⚠ Common exam trap
Candidates often confuse build or source control actions (CodeBuild, CodeCommit) with deployment actions, or mistake event-driven invocations (S3 triggers) for deployment mechanisms, leading them to select options that are valid for other purposes but not for deploying Lambda functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation to update the Lambda function's stack.
AWS CloudFormation can manage Lambda function deployments as part of a stack update. By defining the Lambda function resource in a CloudFormation template, CodePipeline can trigger a stack update that creates or updates the function, ensuring infrastructure-as-code best practices and consistent deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS CloudFormation to update the Lambda function's stack.
Why this is correct
CloudFormation is an infrastructure-as-code service that declares the entire serverless application stack, including the Lambda function, IAM role, event source mappings, and environment variables. Updating the stack applies code and configuration changes in a deterministic order and supports rollback on failure, making it a valid CI/CD deployment step. It treats the Lambda function as a managed resource, and can be invoked via CodePipeline or directly. This is a correct approach because it ensures drift-free, auditable releases.
- ✗
Use Amazon S3 to trigger the Lambda function deployment.
Why it's wrong here
Amazon S3 is a highly durable object store, not a deployment control plane. While S3 can store your Lambda deployment artifacts (ZIP/JAR) and can be configured to send an event notification when an object is uploaded, that event can only invoke a downstream consumer like Lambda or SQS—it has no native capability to update another Lambda function's code or configuration. Relying on S3 events would conflate data-plane activity (object writes) with control-plane deployment actions, and it cannot manage parameters, aliases, or rollbacks.
- ✗
Use AWS CodeBuild to directly deploy the Lambda function.
Why it's wrong here
CodeBuild is a managed build service that performs compilation, static analysis, and generation of artifacts based on a buildspec; it is not a deployment service. It lacks native deployment actions such as updating a Lambda function's code, publishing a version, or shifting traffic, though you could script those actions with AWS CLI in the buildspec as a hack. The proper deployment stage is CodeDeploy or CloudFormation, not CodeBuild, which should stop after producing the artifact.
- ✗
Use AWS CodeCommit to push the Lambda code.
Why it's wrong here
CodeCommit is a Git-based version control repository, and pushing code to it simply updates the source history; it has no deployment capability or integrated action to publish a Lambda function. While CodeCommit can trigger a pipeline via CloudWatch Events, the commit is just an input event, not a mechanism that performs the deployment. It is a source-stage service only, and the same is true for any source control—it cannot directly change the state of deployed resources.
- ✓
Use AWS CodeDeploy to deploy the Lambda function with traffic shifting.
Why this is correct
CodeDeploy is the designated service for managing application deployments, and it natively supports Lambda with deployment configurations such as Canary10Percent5Minutes, Linear10PercentEvery1Minute, and AllAtOnce. It uses an AppSpec file to define the Lambda version that should be deployed and, during traffic shifting, monitors CloudWatch alarms to automatically roll back if errors exceed a threshold. Because it provides granular control over traffic routing with built-in safety mechanisms, it is a correct deployment choice for serverless applications.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.