DOP-C02 SDLC Automation Practice Question
A company uses AWS CodeBuild to run unit tests and package a Node.js application. The buildspec.yml file includes commands to install dependencies using npm. The build is failing with the error: 'npm ERR! code EACCES'. How should a DevOps engineer resolve this issue?
⚠ Common exam trap
Watch out — candidates often assume the EACCES error is a network or VPC issue (Option A) or that sudo is a quick fix (Option B), but the exam tests knowledge of npm's behavior in CI/CD and the deterministic install method 'npm ci' as the proper solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 'npm ci' instead of 'npm install' and ensure a package-lock.json is present
The EACCES error in CodeBuild indicates a permission issue when npm tries to write to the node_modules directory. The default CodeBuild user (usually 'codebuild-user') lacks write permissions to the project root, which is owned by root. Using 'npm ci' (clean install) is the correct resolution because it bypasses the permission issue by using the package-lock.json to install dependencies deterministically, and it does not attempt to modify the lock file or run lifecycle scripts that may require elevated permissions. Additionally, 'npm ci' is faster and more reliable in CI/CD environments like CodeBuild.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the CodeBuild project to use a custom VPC with a NAT gateway for internet access
Why it's wrong here
Configuring a custom VPC with a NAT gateway is a network-level change that does not address the reported npm permission failure. CodeBuild's managed workers already have outbound internet access to reach the npm registry, so the build is not failing due to lack of connectivity. Adding a custom VPC, subnets, and a NAT gateway adds operational complexity and cost without altering the filesystem permissions that npm encounters during install.
- ✗
Configure the buildspec to run npm install with sudo
Why it's wrong here
The CodeBuild build environment runs as an IAM user with limited privileges, and `sudo` is not consistently available in the standard container images. Even if sudo could be invoked, elevating privileges to run `npm install` would only mask the underlying permissions problem and is explicitly discouraged in CI/CD pipelines because it can cause global package files to be written outside expected locations. The correct resolution is to use a dependency installation method that works with the existing user permissions.
- ✗
Add a command to change the ownership of the node_modules directory to the current user
Why it's wrong here
Changing ownership of the local `node_modules` directory is ineffective because the EACCES error typically arises when npm attempts to write global packages to a root-owned system directory, such as `/usr/lib/node_modules`, not the project-local folder. The build creates a fresh working directory for each run, so local directory modifications are ephemeral and do not persist. Furthermore, `node_modules` may not even exist at the time of installation, so ownership commands would target an empty or missing path.
- ✓
Use 'npm ci' instead of 'npm install' and ensure a package-lock.json is present
Why this is correct
Running `npm ci` instead of `npm install` is the recommended fix because it performs a clean, lockfile-driven installation and never attempts to modify the global package cache, thus eliminating the permission conflict. The presence of a valid `package-lock.json` ensures that exact dependency versions are resolved and installed without npm calculating a new dependency tree, which can trigger hidden writes to system locations. This approach is purpose-built for CI/CD pipelines and greatly reduces the chance of inconsistent state or permission failures.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.