Courseiva
Security and Compliance →mediumMultiple Select

DOP-C02 Security and Compliance Practice Question

A company uses AWS CodePipeline for CI/CD. The security team requires that all code changes be scanned for secrets before deployment. The pipeline consists of a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The security team wants to automatically scan for secrets and block the pipeline if any secrets are found. Which THREE actions should the team take? (Choose THREE.)

⚠ Common exam trap

DOP-C02 often tests the misconception that scanning can happen in the deploy stage or that S3 bucket policies can detect secrets — the correct pattern is to scan in the build stage and fail the build on detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the build project to fail the build if the scanning tool returns a non-zero exit code.

Option B is correct because CodeBuild treats a non-zero exit code from a build command as a build failure, which stops the pipeline before the deploy stage and thereby blocks deployment when secrets are detected. Option C is correct because the build stage is the appropriate place to run a secret-scanning tool, and CodePipeline supports invoking it either as a custom action or via a pre-built third-party action from AWS Marketplace integrated into the build stage. Option E is correct because CodeBuild needs its service role to have the necessary permissions (for example, s3:GetObject on the specific bucket/object) to download the scanning tool or its dependencies from Amazon S3 during the build. Option A is not appropriate because scanning after deployment is too late—secrets would already be exposed in the deployed environment, and CodeDeploy does not natively support a scanning action that blocks based on findings. Option D is incorrect because an S3 bucket policy cannot detect secrets in code and is unrelated to blocking a CodePipeline deployment based on scan results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a scanning action in the deploy stage to scan after deployment.

    Why it's wrong here

    Adding a scan action to the deploy stage only executes after the artifact has already been pushed to the target environment. Because the pipeline proceeds through the deploy stage before that action runs, any secret exposed in the artifact has already been live in production, requiring an emergency rollback. Shifting left to the build stage with a failure gate prevents release of tainted artifacts entirely.

  • ✓

    Configure the build project to fail the build if the scanning tool returns a non-zero exit code.

    Why this is correct

    CodeBuild treats any command that returns a non-zero exit code as a failed build, which immediately stops the pipeline and prevents the artifact from being promoted to the deploy stage. When a secret-scanning tool detects an issue, it exits with a non-zero code; configuring the build project to treat that as fatal ensures the pipeline is blocked before deployment. This is often implemented in the buildspec by running the scanner as the final command or using build phases with explicit failure handling.

  • ✓

    Add a scanning action in the build stage using a custom action or a third-party action from AWS Marketplace.

    Why this is correct

    You can integrate a custom or AWS Marketplace scanning action directly into the build stage of the pipeline to inspect the artifact immediately after compilation. This action can invoke a Lambda function, a partner solution, or an AWS CodeBuild-backed action that runs the scanner and can fail the stage if it detects secrets. This approach gives you a dedicated pipeline step for security scanning, separate from the build project itself, and makes the gate explicit and auditable in the pipeline structure.

  • ✗

    Configure an S3 bucket policy to deny access if secrets are detected.

    Why it's wrong here

    S3 bucket policies grant or deny access based on IAM principals, actions, resources, and request conditions; they have no mechanism to inspect object content for secrets such as API keys or passwords. Even if such a policy could be written, denying access after a secret is already in the bucket does nothing to prevent the secret from being packaged into an artifact and deployed. Secret detection requires content-aware scanning by code analysis tools, not a coarse-grained authorization layer.

  • ✓

    Grant the CodeBuild service role permissions to retrieve the scanning tool from an S3 bucket.

    Why this is correct

    The CodeBuild service role must have s3:GetObject permission (and, if listing is required, s3:ListBucket) to download a scanning tool or its definitions from a private S3 bucket during the install phase. Without that permission, the build fails at the download step, so granting the correct policy is a necessary prerequisite for running the scanner inside the build project. This is not the enforcement mechanism itself; it must be paired with a buildspec that invokes the tool and a non-zero exit failure to actually block the pipeline.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.