DOP-C02 SDLC Automation Practice Question
A company uses AWS CloudFormation to manage infrastructure. The DevOps engineer wants to implement a CI/CD pipeline that builds and tests a CloudFormation template and then deploys it across multiple AWS accounts. Which combination of services should the engineer use?
⚠ Common exam trap
A common mix-up: candidates confuse CodeDeploy with CloudFormation deployment actions, or assume that a single CodeBuild project can handle cross-account deployments without understanding the need for IAM role assumption and pipeline-level orchestration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use CodePipeline with separate CodeBuild projects for validation and CloudFormation deployment actions assuming IAM roles in target accounts.
It uses CodePipeline to orchestrate the CI/CD workflow, with separate CodeBuild projects for template validation (e.g., cfn-lint) and deployment actions that assume IAM roles in target accounts. This design ensures cross-account access via role assumption, which is the recommended pattern for multi-account deployments, and separates validation from deployment for better control and rollback.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use CodeBuild to run cfn-lint and then use AWS Lambda to deploy stacks across accounts.
Why it's wrong here
While CodeBuild is a valid place to run cfn-lint, offloading the actual stack provisioning to AWS Lambda is circuitous: you must write and maintain custom code that cycles through target accounts, manually assumes IAM roles, monitors stack events, and implements retry/rollback logic. Lambda's 15-minute execution limit and lack of built-in artifact tracking also make this an anti-pattern for complex multi-account builds. CodePipeline's native CloudFormation deployment action handles these concerns declaratively, making the Lambda-based approach needlessly complex.
- ✓
Use CodePipeline with separate CodeBuild projects for validation and CloudFormation deployment actions assuming IAM roles in target accounts.
Why this is correct
CodePipeline natively orchestrates cross-account deployments through its CloudFormation action, which can be configured with a role ARN to assume in each target account. A dedicated CodeBuild project running cfn-lint performs static validation in an isolated build stage, while subsequent CloudFormation deployment actions use that assumed role to create or update stacks per account. This separation allows you to add manual approvals, run parallel deployments, and reuse the same artifact across accounts without embedding cloud logic in a single script.
- ✗
Use CodePipeline with CodeDeploy to deploy CloudFormation stacks across accounts.
Why it's wrong here
CodeDeploy is purpose-built to roll out application code or revisions to compute services like EC2, Lambda, or on-premises servers; it has no concept of CloudFormation templates or infrastructure stacks. Its deployment model centers on AppSpec files, lifecycle hooks, and deployment groups to manage traffic, not on provisioning AWS resources. Therefore, attempting to use CodeDeploy to deploy CloudFormation stacks would require significant workarounds and still wouldn't provide the native stack lifecycle management that the CloudFormation deploy action in CodePipeline offers.
- ✗
Use CodePipeline with a single CodeBuild project to run cfn-lint and deploy to all accounts.
Why it's wrong here
A single CodeBuild project executes under one static IAM role and a single set of environment variables, so deploying to multiple target accounts would force you to write bespoke 'assume role' calls inside the build script, hard-code account mappings, and manually handle parallel or sequential deployments. This monolithic approach also intertwines linting with infrastructure provisioning, meaning a failure in one account's deployment could block others and prevent CodePipeline from applying stage-level gates like approvals. Better practice is to let CodeBuild only validate templates and delegate the per-account deployment to CloudFormation actions that each assume the appropriate target-account role.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CloudFormation to manage infrastructure. The DevOps team wants to deploy a stack across multiple accounts using AWS CodePipeline. Which approach is BEST for automating cross-account deployments?
easy- A.Use AWS CloudFormation StackSets to deploy the stack across accounts.
- B.Create a separate pipeline in each account and trigger them manually.
- ✓ C.Use a single pipeline in the management account with IAM roles that assume cross-account roles.
- D.Use an S3 bucket with cross-account access and Lambda to invoke CloudFormation.
Why C: AWS CodePipeline can assume an IAM role in the target account (via a cross-account role) to perform CloudFormation deployments. This allows a single pipeline in the management account to automate deployments across multiple accounts without manual triggers or separate pipelines, adhering to the principle of least privilege and centralized control.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.