DOP-C02 Security and Compliance Practice Question
A company uses AWS CodePipeline for CI/CD. The security team requires that all code changes be scanned for secrets before deployment. The pipeline consists of a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The security team wants to automatically scan for secrets and block the pipeline if any secrets are found. Which THREE actions should the team take? (Choose THREE.)
⚠ Common exam trap
DOP-C02 often tests the misconception that scanning can happen in the deploy stage or that S3 bucket policies can detect secrets — the correct pattern is to scan in the build stage and fail the build on detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the build project to fail the build if the scanning tool returns a non-zero exit code.
Option B is correct because CodeBuild treats a non-zero exit code from a build command as a build failure, which stops the pipeline before the deploy stage and thereby blocks deployment when secrets are detected. Option C is correct because the build stage is the appropriate place to run a secret-scanning tool, and CodePipeline supports invoking it either as a custom action or via a pre-built third-party action from AWS Marketplace integrated into the build stage. Option E is correct because CodeBuild needs its service role to have the necessary permissions (for example, s3:GetObject on the specific bucket/object) to download the scanning tool or its dependencies from Amazon S3 during the build. Option A is not appropriate because scanning after deployment is too late—secrets would already be exposed in the deployed environment, and CodeDeploy does not natively support a scanning action that blocks based on findings. Option D is incorrect because an S3 bucket policy cannot detect secrets in code and is unrelated to blocking a CodePipeline deployment based on scan results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a scanning action in the deploy stage to scan after deployment.
Why it's wrong here
Adding a scan action to the deploy stage only executes after the artifact has already been pushed to the target environment. Because the pipeline proceeds through the deploy stage before that action runs, any secret exposed in the artifact has already been live in production, requiring an emergency rollback. Shifting left to the build stage with a failure gate prevents release of tainted artifacts entirely.
- ✓
Configure the build project to fail the build if the scanning tool returns a non-zero exit code.
Why this is correct
CodeBuild treats any command that returns a non-zero exit code as a failed build, which immediately stops the pipeline and prevents the artifact from being promoted to the deploy stage. When a secret-scanning tool detects an issue, it exits with a non-zero code; configuring the build project to treat that as fatal ensures the pipeline is blocked before deployment. This is often implemented in the buildspec by running the scanner as the final command or using build phases with explicit failure handling.
- ✓
Add a scanning action in the build stage using a custom action or a third-party action from AWS Marketplace.
Why this is correct
You can integrate a custom or AWS Marketplace scanning action directly into the build stage of the pipeline to inspect the artifact immediately after compilation. This action can invoke a Lambda function, a partner solution, or an AWS CodeBuild-backed action that runs the scanner and can fail the stage if it detects secrets. This approach gives you a dedicated pipeline step for security scanning, separate from the build project itself, and makes the gate explicit and auditable in the pipeline structure.
- ✗
Configure an S3 bucket policy to deny access if secrets are detected.
Why it's wrong here
S3 bucket policies grant or deny access based on IAM principals, actions, resources, and request conditions; they have no mechanism to inspect object content for secrets such as API keys or passwords. Even if such a policy could be written, denying access after a secret is already in the bucket does nothing to prevent the secret from being packaged into an artifact and deployed. Secret detection requires content-aware scanning by code analysis tools, not a coarse-grained authorization layer.
- ✓
Grant the CodeBuild service role permissions to retrieve the scanning tool from an S3 bucket.
Why this is correct
The CodeBuild service role must have s3:GetObject permission (and, if listing is required, s3:ListBucket) to download a scanning tool or its definitions from a private S3 bucket during the install phase. Without that permission, the build fails at the download step, so granting the correct policy is a necessary prerequisite for running the scanner inside the build project. This is not the enforcement mechanism itself; it must be paired with a buildspec that invokes the tool and a non-zero exit failure to actually block the pipeline.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.