DOP-C02 SDLC Automation Practice Question
A company is implementing a CI/CD pipeline for a microservices architecture on Amazon ECS. The pipeline must deploy to multiple environments (dev, test, prod) in sequence with manual approval gates between environments. Which two AWS services should be used together to meet these requirements? (Choose TWO.)
⚠ Common exam trap
Many candidates confuse AWS CodeDeploy with AWS CodeBuild or AWS CloudFormation, mistakenly thinking that a build or infrastructure tool can also handle the deployment sequencing and manual approval gates, when in fact CodePipeline is the only service that orchestrates the pipeline flow and CodeDeploy is the service that performs the actual ECS deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CodePipeline
AWS CodePipeline (A) is correct because it provides the orchestration framework to model the CI/CD pipeline with sequential stages for dev, test, and prod environments, including built-in support for manual approval gates between stages. AWS CodeDeploy (D) is correct because it integrates directly with CodePipeline to handle the actual deployment of containerized applications to Amazon ECS, supporting blue/green deployments and traffic shifting for microservices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CodePipeline
Why this is correct
AWS CodePipeline is the correct orchestrator for a CI/CD pipeline because it provides end-to-end workflow management, defining stages for source, build, test, deployment, and manual approval gates. It can trigger CodeBuild to build and push a container image, then use CodeDeploy or an ECS deploy action to update the ECS service, and even pause between environments (e.g., staging to production) for human sign-off. Its role is to coordinate the sequence and dependencies, not to execute the build or deployment itself, making it the central control plane for the pipeline.
- ✗
AWS CodeBuild
Why it's wrong here
AWS CodeBuild is a fully managed build service that compiles source code, runs unit tests, and produces build artifacts such as a packaged application or a Docker container image. It cannot deploy the built artifact to ECS—it only executes the build phase and publishes the artifact to a repository like Amazon ECR. While CodeBuild is often a stage within a CodePipeline, it lacks the ability to manage ECS service updates, traffic shifting, or approval gates, so it cannot serve as the deployment or orchestration engine.
- ✗
AWS CloudFormation
Why it's wrong here
AWS CloudFormation is an infrastructure-as-code service that provisions and manages AWS resources—such as ECS clusters, task definitions, services, load balancers, and IAM roles—using declarative templates. It can define the entire environment but does not handle the application release lifecycle (e.g., deploying a new container image version across a running service with traffic shifting). Additionally, CloudFormation does not natively include approval gates or stage-based promotion for CI/CD; it is designed for infrastructure updates, not orchestration of code deployments.
- ✓
AWS CodeDeploy
Why this is correct
AWS CodeDeploy is the service that executes the actual deployment to AWS ECS, supporting blue/green deployment, canary, and linear traffic-shifting strategies. It takes an AppSpec file to define how to load the new task set and reroute traffic, and it integrates with the ECS service to manage task replacement and rollbacks. However, CodeDeploy is a deployment engine that needs to be invoked by an orchestrator; it does not provide the overall pipeline structure, source/building stages, or multi-stage approval workflow, so it is a correct participant but not the correct orchestrator.
- ✗
AWS Elastic Beanstalk
Why it's wrong here
AWS Elastic Beanstalk is a platform-as-a-service that automates provisioning of EC2 instances, load balancers, autoscaling, and application health monitoring for web applications. It uses its own managed platform and deployment mechanisms, which are not compatible with a custom ECS microservices architecture where you need fine-grained control over ECS task definitions, service discovery, and network configurations. Elastic Beanstalk is not designed to deploy to an existing ECS cluster or integrate with an ECS-based CI/CD pipeline, making it an unsuitable choice for this scenario.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.