Courseiva
Security and Compliance →hardMultiple Select

DOP-C02 Security and Compliance Practice Question

A company is designing a secure CI/CD pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy. The pipeline must deploy to an EC2 Auto Scaling group across multiple AWS accounts. The security requirements include: (1) no hardcoded credentials, (2) least privilege for cross-account access, (3) encrypted artifacts. Which THREE steps should the DevOps engineer implement? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a customer-managed KMS key with a cross-account key policy to encrypt artifacts.

Using a customer-managed KMS key with a cross-account key policy allows encrypting artifacts in CodePipeline's artifact store, ensuring that only authorized accounts can decrypt them, meeting the requirement for encrypted artifacts and least privilege. Option B is correct because storing database credentials in AWS Secrets Manager and retrieving them in CodeBuild using the secrets manager action avoids hardcoded credentials and provides secure, rotating credentials. Option E is correct because configuring CodePipeline to assume an IAM role in the target account using a trust policy enables cross-account deployment with least privilege, as the pipeline assumes a role with only necessary permissions. Option C is incorrect because while SSM Parameter Store can store credentials, Secrets Manager is specifically designed for secrets management with automatic rotation and is more appropriate for database credentials. Option D is incorrect because CodeCommit with pull request approval rules is a source control practice, not directly addressing the security requirements of no hardcoded credentials, least privilege cross-account access, or encrypted artifacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a customer-managed KMS key with a cross-account key policy to encrypt artifacts.

    Why this is correct

    Using a customer-managed KMS key with a cross-account key policy is correct because CodePipeline stores build artifacts in S3, which must be encrypted. By default, AWS-managed keys are scoped to a single account, so to share artifacts with a target account you must use a customer-managed key and explicitly grant the target account's principals decrypt permission via a cross-account key policy. This provides secure, auditable cross-account artifact transfer without exposing the key material, and it lets you enforce encryption at rest with full control over key rotation and access.

  • ✓

    Store database credentials in AWS Secrets Manager and retrieve them in CodeBuild using the secrets manager action.

    Why this is correct

    Retrieving database credentials from AWS Secrets Manager in CodeBuild is correct and is the recommended practice for secrets in a CI/CD pipeline. Secrets Manager offers automatic rotation, fine-grained IAM policies, and the built-in 'secrets manager' action in CodeBuild can fetch secrets as environment variables at build time, eliminating any hardcoded or stored credentials. This approach also enables versioning and audit trail for secret access, which is critical for production database connections.

  • ✗

    Store database credentials in AWS Systems Manager Parameter Store and retrieve them in CodeBuild.

    Why it's wrong here

    Using AWS Systems Manager Parameter Store to store database credentials is not the best choice because Parameter Store is designed primarily for configuration data like parameter values, not high-security secrets. While it can store secrets, it lacks native automatic rotation and does not provide the same level of integration with CodeBuild's secrets-specific actions. For credentials, Secrets Manager is explicitly intended and more secure, so this option does not meet the design's security requirements.

  • ✗

    Use AWS CodeCommit as the source repository with pull request approval rules.

    Why it's wrong here

    Using AWS CodeCommit as the source repository with pull request approval rules is not directly relevant to the stated security concerns of credentials and cross-account access. This option improves code review and change management within the source control layer, but it does not address how the pipeline securely obtains database secrets or how it gains permission to deploy into the target account. Therefore, it is an incomplete solution for the pipeline's cross-account and secrets-handling requirements.

  • ✓

    Configure CodePipeline to assume an IAM role in the target account using a trust policy.

    Why this is correct

    Configuring CodePipeline to assume an IAM role in the target account using a trust policy is correct because it provides a secure, temporary-credentials based mechanism for cross-account deployment. The pipeline's service role in the source account is granted permission in the target role's trust policy to assume it, and the target role carries an IAM policy that allows the required deployment actions. This avoids static access keys or storing long-lived credentials, and it is a standard AWS pattern for federated access between accounts.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.