Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 Commit signature verification Practice Question

A company uses AWS CodeCommit for source control. Developers work on feature branches and create pull requests to merge into the 'develop' branch. The company wants to enforce that all commits to the 'develop' branch are signed. Which AWS service or feature should be used to enforce this policy?

⚠ Common exam trap

The trap is that candidates may think CodeCommit lacks native support for signed commits and resort to a custom Lambda-based solution. In reality, CodeCommit approval rule templates can enforce commit signing directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an approval rule template in CodeCommit that requires commits to be signed and associate it with the 'develop' branch.

AWS CodeCommit natively supports enforcing signed commits. You can create an approval rule template with the 'Require commit signing' condition and associate it with the 'develop' branch. This ensures that any commit to the branch must be signed with a valid GPG key, and unsigned commits are rejected. Option A is incorrect because using CloudWatch Events and Lambda to revert unsigned commits is not a native enforcement mechanism and is unnecessary. Option C is incorrect because KMS is not used for Git commit signing. Option D is incorrect because IAM policies cannot inspect commit signatures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon CloudWatch Events to trigger a Lambda function that verifies commit signatures and reverts unsigned commits.

    Why it's wrong here

    Correct. CloudWatch Events can trigger a Lambda function to verify commit signatures. The Lambda can reject or revert unsigned commits, enforcing the policy.

  • ✓

    Create an approval rule template in CodeCommit that requires commits to be signed and associate it with the 'develop' branch.

    Why this is correct

    Incorrect. Approval rule templates only require approvals from specified users; they do not verify commit signatures or enforce signing.

  • ✗

    Use AWS Key Management Service (KMS) to create a signing key and require developers to use it.

    Why it's wrong here

    Incorrect. KMS can be used to create signing keys, but it does not enforce signing on commits automatically; it only provides the keys.

  • ✗

    Configure an IAM policy that denies 'git push' unless the commit is signed.

    Why it's wrong here

    Incorrect. IAM policies cannot inspect commit content or verify signatures; they can only control API-level permissions like git push, but not check if the commit is signed.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.