DOP-C02 CodePipeline Stages Practice Question
A company uses AWS CodePipeline for CI/CD. A recent deployment to an Amazon ECS service failed because the new task definition referenced an ECR image that does not exist. The pipeline uses a source stage (CodeCommit), build stage (CodeBuild), and deploy stage (ECS). The engineer wants to catch such errors earlier. What should the engineer add to the pipeline?
⚠ Common exam trap
DOP-C02 often tests the concept of adding validation stages to catch errors early. Candidates may think that a manual approval or a Lambda invoke is the answer, but the most straightforward and integrated solution is a test stage using CodeBuild. The trap is overlooking the simplicity of a script-based test stage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a test stage that runs a script to verify the image exists in ECR.
Adding a test stage that runs a script to verify the image exists in ECR will catch the error earlier in the pipeline, before the deploy stage. This test stage can use AWS CLI or SDK to check if the image tag exists in the ECR repository, and fail the pipeline if it does not. This prevents the deployment from proceeding with a non-existent image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an invoke action that calls a Lambda function to check the image.
Why it's wrong here
Adding a Lambda function to check the image would occur after the build stage, which is not the earliest point to catch a non-existent ECR image. CodeBuild, within the build stage, is responsible for creating and pushing the image, and its buildspec can be configured to validate the image's existence or successful push directly. Lambda invoke actions are useful for custom validations or orchestrating external services between pipeline stages, such as triggering security scans or updating external systems, where the logic isn't native to the preceding action.
- ✗
Add a manual approval step before the deploy stage.
Why it's wrong here
A manual approval step only inserts a human gate and does not perform any automated check against ECR; an approver may not verify the image tag, and approving would not fix a missing image. It adds latency to the pipeline and masks the need for an automated existence check, while also failing to distinguish between a missing artifact and a legitimate infrastructure change. Since the failure is a technical issue, a programmatic verification is required, not human sign-off.
- ✓
Add a test stage that runs a script to verify the image exists in ECR.
Why this is correct
Adding a test stage immediately after the build stage with a script using the AWS CLI or SDK to call ecr:DescribeImages for the specific repository and image tag validates that the expected artifact exists before deployment. This automated gate runs in every pipeline execution, catches missing or mis-tagged images at the earliest practical point, and fails the pipeline with a clear error rather than letting the deploy stage fail late. It is the correct, lightweight fix that does not alter build behavior.
- ✗
Add a second build stage that re-builds the image.
Why it's wrong here
Adding a second build stage would simply re-execute the build process from source, which may succeed and push a new image rather than verifying that the previously published image exists in ECR. This does not serve as a validation gate; it can mask the root cause by recreating the artifact, and it adds unnecessary build time and cost. A correct fix should compare the expected repository and image tag against ECR, not regenerate the image.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.