DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CodeBuild to build and test their application. They want to integrate Infrastructure as Code (IaC) scanning into their build pipeline to detect security misconfigurations in CloudFormation templates before deployment. Which TWO tools or services can be used for this purpose? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse AWS Config (which evaluates deployed resources) with a pre-deployment scanning tool, or assume Security Hub can scan templates directly, when in fact both operate on live infrastructure, not on template files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudFormation Guard
AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to enforce compliance and security best practices on CloudFormation templates. It can be integrated into a CodeBuild pipeline to scan templates for misconfigurations before deployment, making it a correct choice for IaC security scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudFormation Guard
Why this is correct
CloudFormation Guard is a policy-as-code engine from AWS that uses a Guard-specific DSL to define rules for template properties like encryption, tags, and allowed resource types. It reads CloudFormation JSON/YAML directly and can be invoked in CodeBuild via the `cfn-guard` CLI to fail the build when a violation is found. This enables automated, pre-deployment compliance checks, which is exactly what the scenario requires.
- ✗
AWS Security Hub
Why it's wrong here
Security Hub ingests and aggregates security findings from services such as GuardDuty, Inspector, and IAM Access Analyzer, then scores them against standards like CIS AWS Foundations. It does not accept raw CloudFormation templates as input, nor does it parse template structure to enforce organizational policy. Its value is in identifying issues in already-deployed resources, making it ineffective for pre-deployment template scanning.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks configuration changes of provisioned AWS resources, evaluating them against managed or custom rules and recording a history for auditing and drift detection. It only sees the final state of resources after CloudFormation has deployed them, so it cannot assess a template's content before creation. Because the CI/CD stage here needs to evaluate the template artifact itself, Config offers no static-analysis capability for that input.
- ✗
HashiCorp Terraform
Why it's wrong here
Terraform is an infrastructure-as-code tool that manages resources via its own HCL syntax and state files; its validation commands (`terraform validate`, `tflint`) only understand Terraform configuration. It has no built-in ability to parse or evaluate CloudFormation templates, and CloudFormation does not accept Terraform plans. Adding Terraform to the CodeBuild pipeline to scan the template would introduce a mismatch of IaC dialects and provide no useful output.
- ✓
cfn-nag
Why this is correct
cfn-nag is an open-source static analysis tool specifically designed to scan CloudFormation templates for security anti-patterns like IAM wildcard actions, world-open security groups, and unencrypted storage. It can be executed as a step in CodeBuild, and a non-zero exit code from a violation will stop the build. While not an AWS service, it complements template validation and is commonly used for pre-deployment security checks.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.