DOP-C02 SDLC Automation Practice Question
A company uses AWS CodeCommit for source control and wants to enforce that all commits to the main branch are signed. The DevOps team has configured Git commit signing using GPG keys. However, some developers are able to push unsigned commits to main. What should the engineer do to enforce signed commits?
⚠ Common exam trap
Many candidates assume AWS CodeCommit has a built-in 'require signed commits' toggle like GitHub or GitLab, but AWS CodeCommit requires a custom serverless solution (Lambda trigger) to enforce this, and the exam tests your ability to recognize when native features are absent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an AWS CodeCommit trigger with an AWS Lambda function that validates commit signatures and rejects unsigned commits.
AWS CodeCommit does not natively support a 'require signed commits' setting like GitHub or GitLab. To enforce signed commits, you must use a CodeCommit trigger that invokes an AWS Lambda function to validate the GPG signature of each commit pushed to the main branch. The Lambda function can parse the commit object, verify the signature using the developer's public key, and reject the push by returning an error if the commit is unsigned or the signature is invalid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the 'requireSignedCommits' parameter in the repository configuration to 'true'.
Why it's wrong here
This is invalid because CodeCommit does not expose any repository configuration parameter named requireSignedCommits. CodeCommit repository settings let you name the repo, attach tags, set triggers, and configure notifications, but it has no native server-side toggle for enforcing signed commits. The idea of a one-click signed-commit enforcement exists in other Git hosting services, but not here, so this option cannot work.
- ✗
Configure branch protection rules in IAM to deny push access to main unless the commit is signed.
Why it's wrong here
IAM policies are based on attributes of the API request, such as principal, resource, and condition keys like codecommit:References or aws:SourceIp. They cannot evaluate the Git commit payload, including whether the commit was signed with a GPG key. CodeCommit simply does not expose a condition key for commit signature status; thus IAM can deny based on branch or IP, but can never condition on signature validity.
- ✓
Use an AWS CodeCommit trigger with an AWS Lambda function that validates commit signatures and rejects unsigned commits.
Why this is correct
CodeCommit triggers invoke a Lambda function asynchronously when a reference is updated, and that Lambda can inspect the pushed commit objects using the Git command line or the CodeCommit API to verify GPG signatures. Although the trigger fires after the push is initially accepted, the Lambda can delete or restore the branch reference to its previous commit via the UpdateRef API, effectively rejecting the unsigned commit and preserving repository integrity. This is the practical way to enforce signed commits because CodeCommit itself has no native, built-in signed-commit enforcement.
- ✗
Create a repository policy that denies git push actions unless the condition 'codecommit:References' and 'codecommit:SourceIp' match.
Why it's wrong here
A repository policy with conditions on codecommit:References and codecommit:SourceIp can restrict which branch is updated and the IP address of the caller, but these are request-context attributes, not properties of the Git objects being pushed. The policy engine cannot inspect the commit contents, so an unsigned commit that comes from an allowed IP and targets the main branch would still pass. Such a policy narrows the attack surface but absolutely cannot detect or block unsigned commits.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CodeCommit as a Git repository. Developers want to enforce that all commits are signed with GPG keys. How can this be achieved?
medium- A.Configure a Git hook in the repository to reject unsigned commits.
- B.Use an IAM policy condition to deny pushes if the commit is not signed.
- C.Enable the 'Require GPG signatures' option in the CodeCommit repository settings.
- ✓ D.Ask developers to sign commits locally and use a pre-commit hook.
Why D: AWS CodeCommit does not natively support server-side GPG signature verification or a repository-level setting to require signed commits. The most practical way to enforce signed commits is through client-side Git hooks. Option D describes this approach: developers sign commits locally and a pre-commit hook ensures that every commit is signed before it is created. While not foolproof (developers can bypass the hook), it is the only viable method among the options that aligns with CodeCommit's capabilities. Option A misinterprets 'Git hook in the repository' as a server-side hook, which CodeCommit does not support. Option B is incorrect because IAM policies cannot evaluate commit signature status. Option C is incorrect because CodeCommit lacks such a native setting.
Variation 2. A team is using AWS CodeCommit as their version control system. They want to ensure that all commits are signed with a GPG key. What is the simplest way to enforce this?
easy- A.Use AWS CloudTrail to monitor unsigned commits and automatically revert them.
- B.Use a pre-commit hook in the local repository to enforce signing.
- C.Configure an IAM policy that denies PutFile if the commit is not signed.
- ✓ D.Enable the 'Require signed commits' option in the CodeCommit repository settings.
Why D: AWS CodeCommit provides a built-in repository setting called 'Require signed commits' that, when enabled, rejects any push containing unsigned commits at the server side. This is the simplest and most reliable enforcement mechanism because it does not rely on client-side configurations or custom scripts, and it leverages CodeCommit's native integration with GPG signature verification.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.