DOP-C02 SDLC Automation Practice Question
A company is using AWS CodeBuild to compile and test code. The buildspec.yml file includes a pre_build phase that installs dependencies and a build phase that runs the compilation. The tests are run in the post_build phase. The team wants to improve the security of the build process by ensuring that sensitive information such as database passwords is not exposed in the build logs. Which TWO actions should the team take? (Choose two.)
⚠ Common exam trap
Many exam-takers think restricting log access (Option C) or encrypting logs (Option D) is sufficient to protect secrets, but the core requirement is to prevent secrets from ever being written to logs in the first place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Systems Manager Parameter Store to store the secrets and reference them in the buildspec using the 'parameter-store' field.
Option A is correct because CodeBuild natively supports the 'parameter-store' field in buildspec.yml, which retrieves values from AWS Systems Manager Parameter Store at build time and injects them as environment variables without printing them in the logs; the build's service role needs ssm:GetParameters permissions. Option B is correct because CodeBuild also supports the 'secrets-manager' field, which fetches secrets from AWS Secrets Manager during the build and masks them in the logs, requiring secretsmanager:GetSecretValue permissions. Option C is not correct because restricting who can view logs does not prevent secrets from being written into the logs in the first place, so the exposure risk remains. Option D is not correct because S3 encryption at rest protects stored log objects but does not stop secrets from appearing in plaintext within the logs. Option E is not correct because plain-text environment variables are visible in the CodeBuild console and can be echoed into build logs, directly exposing the sensitive values.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Systems Manager Parameter Store to store the secrets and reference them in the buildspec using the 'parameter-store' field.
Why this is correct
AWS Systems Manager Parameter Store with the 'parameter-store' field in buildspec is correct because CodeBuild retrieves the SecureString value during build and injects it as an environment variable without ever displaying it in the build log. The value itself is encrypted with KMS and access is controlled by IAM, so this satisfies the requirement to keep secrets out of logs without additional steps.
- ✓
Use AWS Secrets Manager to store the secrets and reference them in the buildspec using the 'secrets-manager' field.
Why this is correct
Similarly, referencing a secret via AWS Secrets Manager using the 'secrets-manager' field is also correct, as CodeBuild fetches the secret value at build time and populates it as an environment variable while suppressing it from all log output. Secrets Manager adds rotation and fine-grained access control, and the secret is never embedded in the buildspec or project configuration, making it a secure and compliant choice.
- ✗
Restrict access to the build logs by using IAM policies to only allow specific users to view them.
Why it's wrong here
Restricting IAM access to build logs only governs who is allowed to view the logs after they are generated; it does not stop the secret from being written into the log output by echo or debug commands during the build. Any user with legitimate log access, or an automated log ingestion process, would still see the plaintext secret, so this is not a preventive control and fails the requirement.
- ✗
Enable encryption at rest for the CodeBuild project's S3 logs.
Why it's wrong here
Enabling S3-side encryption for the CodeBuild log bucket protects the log objects at rest, but it does not alter the fact that the secret is captured in plaintext within the log lines. A user or service with permission to read the logs can still decrypt the log file and recover the secret, because encryption only provides confidentiality while stored, not redaction of content, so it does not meet the goal of keeping secrets out of logs.
- ✗
Store the secrets as plain-text environment variables in the CodeBuild project.
Why it's wrong here
Storing secrets as plain-text environment variables in the CodeBuild project is inherently insecure because the values are visible in the project configuration and are printed to the build log whenever a command like 'env' or an explicit echo is run. CodeBuild offers no mechanism to entirely mask such values from the log output, so this approach directly contradicts the requirement to prevent secret exposure, making it the worst choice.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.