Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CodeBuild to build and test their application. They want to integrate Infrastructure as Code (IaC) scanning into their build pipeline to detect security misconfigurations in CloudFormation templates before deployment. Which TWO tools or services can be used for this purpose? (Choose TWO.)

⚠ Common exam trap

It's easy for candidates to confuse AWS Config (which evaluates deployed resources) with a pre-deployment scanning tool, or assume Security Hub can scan templates directly, when in fact both operate on live infrastructure, not on template files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudFormation Guard

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to enforce compliance and security best practices on CloudFormation templates. It can be integrated into a CodeBuild pipeline to scan templates for misconfigurations before deployment, making it a correct choice for IaC security scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudFormation Guard

    Why this is correct

    CloudFormation Guard is a policy-as-code engine from AWS that uses a Guard-specific DSL to define rules for template properties like encryption, tags, and allowed resource types. It reads CloudFormation JSON/YAML directly and can be invoked in CodeBuild via the `cfn-guard` CLI to fail the build when a violation is found. This enables automated, pre-deployment compliance checks, which is exactly what the scenario requires.

  • ✗

    AWS Security Hub

    Why it's wrong here

    Security Hub ingests and aggregates security findings from services such as GuardDuty, Inspector, and IAM Access Analyzer, then scores them against standards like CIS AWS Foundations. It does not accept raw CloudFormation templates as input, nor does it parse template structure to enforce organizational policy. Its value is in identifying issues in already-deployed resources, making it ineffective for pre-deployment template scanning.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config tracks configuration changes of provisioned AWS resources, evaluating them against managed or custom rules and recording a history for auditing and drift detection. It only sees the final state of resources after CloudFormation has deployed them, so it cannot assess a template's content before creation. Because the CI/CD stage here needs to evaluate the template artifact itself, Config offers no static-analysis capability for that input.

  • ✗

    HashiCorp Terraform

    Why it's wrong here

    Terraform is an infrastructure-as-code tool that manages resources via its own HCL syntax and state files; its validation commands (`terraform validate`, `tflint`) only understand Terraform configuration. It has no built-in ability to parse or evaluate CloudFormation templates, and CloudFormation does not accept Terraform plans. Adding Terraform to the CodeBuild pipeline to scan the template would introduce a mismatch of IaC dialects and provide no useful output.

  • ✓

    cfn-nag

    Why this is correct

    cfn-nag is an open-source static analysis tool specifically designed to scan CloudFormation templates for security anti-patterns like IAM wildcard actions, world-open security groups, and unencrypted storage. It can be executed as a step in CodeBuild, and a non-zero exit code from a violation will stop the build. While not an AWS service, it complements template validation and is commonly used for pre-deployment security checks.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.