Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company is using AWS CodePipeline to deploy a web application across multiple AWS accounts using CloudFormation stack sets. The pipeline is in the tools account, and it deploys to production account. The security team requires that all CloudFormation changes to production account be reviewed and approved by a senior engineer. Which approach meets this requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a manual approval step in the CodePipeline before the CloudFormation deployment stage.

Adding a manual approval step in CodePipeline before the CloudFormation deployment stage allows a senior engineer to review and approve changes, meeting the security requirement. Option A is incorrect because CloudTrail only logs actions after they occur and does not provide a review mechanism. Option B is incorrect because denying CloudFormation actions to all but a specific role would prevent the pipeline from deploying unless it uses that role, but it does not enforce a manual review process. Option D is incorrect because SCPs are preventive controls that block actions, not a mechanism for manual approval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to monitor deployments and send notifications for review.

    Why it's wrong here

    CloudTrail records API activity after the fact and notifications merely alert reviewers; neither halts a stack set deployment pending approval. Auditing and alerting are correct for detective monitoring of changes, not for enforcing a gate before production CloudFormation execution.

  • ✗

    Configure an IAM policy that denies CloudFormation actions in the production account except for a specific role used by the senior engineer.

    Why it's wrong here

    Denying CloudFormation actions except for one role blocks the pipeline but provides no review step, and the senior engineer's own changes bypass approval entirely. Restricting actions to a privileged role suits least-privilege hardening, not a workflow requiring documented approval before deployment.

  • ✓

    Add a manual approval step in the CodePipeline before the CloudFormation deployment stage.

    Why this is correct

    A manual approval action pauses the pipeline before the CloudFormation deploy stage, so a senior engineer must review and approve changes before they reach the production account. This enforces the required human gate on production changes.

  • ✗

    Use a service control policy (SCP) to prevent CloudFormation changes from the tools account.

    Why it's wrong here

    An SCP blocking CloudFormation from the tools account stops deployments outright without any approval mechanism, so approved changes could never proceed. SCPs are correct for organisation-wide guardrails that prohibit entire services or actions across accounts, not for gating individual deployments.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.