DOP-C02 SDLC Automation Practice Question
A company uses AWS CodePipeline to deploy a Node.js application to AWS Elastic Beanstalk. The pipeline includes a build stage that runs 'npm install' and 'npm test'. The team notices that the build stage often fails due to network timeouts when downloading npm packages. Which action would MOST reliably resolve this issue?
⚠ Common exam trap
Test-takers frequently assume increasing timeouts or caching will fix intermittent network failures, but the real issue is a missing outbound internet path when CodeBuild is configured to run inside a VPC without a NAT gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the CodeBuild project to use a VPC with a NAT gateway to the internet.
The network timeouts occur because the CodeBuild project lacks outbound internet access to reach the npm registry. By configuring the CodeBuild project to use a VPC with a NAT gateway, you provide a stable, routable path to the internet via the NAT gateway's elastic IP, eliminating intermittent connectivity issues caused by relying on public endpoints through a non-VPC network path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the CodeBuild project to use a VPC with a NAT gateway to the internet.
Why this is correct
By default, a CodeBuild project that is associated with your Amazon VPC runs in one of your private subnets and has no outbound internet connection unless your route table directs traffic through a NAT gateway. Without that route, `npm install` cannot reach the npm registry and fails with network timeouts. Placing the NAT gateway in a public subnet, updating the private route table to `0.0.0.0/0 -> nat-gateway-id`, and associating the CodeBuild project with that VPC gives the build deterministic, reliable egress to the internet while still allowing it to access any VPC-only resources.
- ✗
Use a custom Docker image that includes pre-installed npm packages.
Why it's wrong here
Baking npm packages into a custom Docker image can reduce or eliminate the need to contact the registry at build time, but it does not address the actual failure mode: CodeBuild has no working network path to the internet. First, CodeBuild must still pull the custom image from Amazon ECR or Docker Hub, which can itself be unreachable without proper egress. Second, if your package.json includes version ranges or lifecycle scripts, npm may still query the registry for metadata or run postinstall scripts that download additional artifacts. This approach is a fragile dependency-management workaround, not a connectivity fix.
- ✗
Enable local dependency caching in the buildspec file.
Why it's wrong here
Enabling local dependency caching in the buildspec (`cache.paths`, e.g., `/root/.npm`) only carries over previously downloaded packages between builds. It cannot help on the initial build or on any cache miss because `npm install` still must contact the registry to resolve and fetch dependencies. Caching is an optimization for builds that have already succeeded at least once; it does nothing to repair the network connection, so the first build would still fail exactly as before.
- ✗
Increase the build timeout to the maximum value.
Why it's wrong here
Increasing the CodeBuild build timeout only changes how long the build can run before CodeBuild terminates it, from the default 60 minutes up to a maximum of 480 minutes. It has no effect on DNS resolution, routing, connectivity, or the speed of the npm registry, and the network connection will still time out. The build will simply run longer, burn more billable minutes, and eventually fail when it hits the new timeout limit, giving no recovery benefit.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.