Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A company uses AWS CodeCommit as a Git repository and CodeBuild for continuous integration. The buildspec.yml file includes steps to run unit tests and package the application. The team wants to ensure that only code from the main branch is deployed to production. They have set up a CodePipeline that triggers on changes to any branch. The pipeline includes a build stage that runs CodeBuild, and then a deploy stage that deploys to production. The team noticed that code from feature branches is being deployed to production accidentally. The team wants to modify the pipeline to prevent this. What is the MOST effective solution?

⚠ Common exam trap

DOP-C02 often tests the confusion between fixing a problem at the source stage versus adding downstream gates — candidates pick manual approval or IAM restrictions when the cleanest fix is the pipeline source branch filter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the CodePipeline source stage, configure the branch filter to only allow the main branch to trigger the pipeline.

The most effective fix is to configure the CodePipeline source stage with a branch filter that only allows the main branch to trigger the pipeline. This prevents feature-branch commits from ever entering the pipeline, stopping the accidental production deployment at the source rather than downstream.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use IAM policies to restrict developers from pushing to the main branch.

    Why it's wrong here

    Restricting IAM permissions prevents developers from updating the main branch directly, but it does not affect how CodePipeline reacts to commits. The pipeline's source stage is configured with a repository and typically a branch pattern; unless that pattern filters to main only, pushes to any branch (e.g., feature/x) will still generate an execution. IAM policies gate user actions, not event-driven pipeline triggering, so they cannot stop the pipeline from running on feature branches.

  • ✓

    In the CodePipeline source stage, configure the branch filter to only allow the main branch to trigger the pipeline.

    Why this is correct

    Configure the CodeCommit source action in the pipeline to specify 'main' as the Branch name; CodePipeline then only initiates an execution when a new commit is pushed to that exact branch. This branch filter is applied at the source stage before any build or deploy action runs, preventing resource consumption for non-main branches. It is the standard, supported mechanism for branch-scoped pipeline behavior in CodePipeline.

  • ✗

    Add a manual approval step before the deploy stage and require approval from a senior engineer.

    Why it's wrong here

    Adding a manual approval step inserts a human gate before the deploy stage, but the pipeline has already run the source, build, and possibly test stages by that point. For a push to a feature branch, the pipeline still triggers, builds, and waits for approval, wasting compute and time. Approval controls what is released, not which events start the pipeline, so it does not solve the 'trigger on every branch' problem.

  • ✗

    Modify the CodeBuild project to only build the main branch by specifying the branch in the source configuration.

    Why it's wrong here

    CodeBuild projects have their own source configuration, including a branch, but when the project is consumed by CodePipeline, the pipeline overrides that source by passing the resolved source artifact and commit ID from the pipeline's source stage. The branch setting in CodeBuild is therefore ignored as a trigger control; the pipeline's source stage is the sole decider of what branch starts an execution. Modifying CodeBuild would only affect standalone builds, not CodePipeline-mediated runs.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.