DOP-C02 Commit signature verification Practice Question
A company uses AWS CodeCommit for source control. Developers work on feature branches and create pull requests to merge into the 'develop' branch. The company wants to enforce that all commits to the 'develop' branch are signed. Which AWS service or feature should be used to enforce this policy?
⚠ Common exam trap
The trap is that candidates may think CodeCommit lacks native support for signed commits and resort to a custom Lambda-based solution. In reality, CodeCommit approval rule templates can enforce commit signing directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an approval rule template in CodeCommit that requires commits to be signed and associate it with the 'develop' branch.
AWS CodeCommit natively supports enforcing signed commits. You can create an approval rule template with the 'Require commit signing' condition and associate it with the 'develop' branch. This ensures that any commit to the branch must be signed with a valid GPG key, and unsigned commits are rejected. Option A is incorrect because using CloudWatch Events and Lambda to revert unsigned commits is not a native enforcement mechanism and is unnecessary. Option C is incorrect because KMS is not used for Git commit signing. Option D is incorrect because IAM policies cannot inspect commit signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon CloudWatch Events to trigger a Lambda function that verifies commit signatures and reverts unsigned commits.
Why it's wrong here
Correct. CloudWatch Events can trigger a Lambda function to verify commit signatures. The Lambda can reject or revert unsigned commits, enforcing the policy.
- ✓
Create an approval rule template in CodeCommit that requires commits to be signed and associate it with the 'develop' branch.
Why this is correct
Incorrect. Approval rule templates only require approvals from specified users; they do not verify commit signatures or enforce signing.
- ✗
Use AWS Key Management Service (KMS) to create a signing key and require developers to use it.
Why it's wrong here
Incorrect. KMS can be used to create signing keys, but it does not enforce signing on commits automatically; it only provides the keys.
- ✗
Configure an IAM policy that denies 'git push' unless the commit is signed.
Why it's wrong here
Incorrect. IAM policies cannot inspect commit content or verify signatures; they can only control API-level permissions like git push, but not check if the commit is signed.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.