DOP-C02 SDLC Automation Practice Question
A company uses AWS CodePipeline to deploy a static website to an S3 bucket. The pipeline includes a source stage (S3), a build stage (CodeBuild) that minifies assets, and a deploy stage that copies files to the production S3 bucket. The deploy stage uses 's3 sync' command. After a recent deployment, some users report seeing old content. What is the MOST likely cause?
⚠ Common exam trap
The trap here is that candidates may focus on S3 permissions or the sync command, overlooking the common real-world scenario where a CDN like CloudFront caches content and requires explicit invalidation after updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The website is served through Amazon CloudFront, and the CloudFront distribution cache was not invalidated after the deployment.
The most likely cause is that the static website is served through Amazon CloudFront, and the CloudFront distribution cache was not invalidated after the deployment. Even though the S3 bucket contents are updated via 's3 sync', CloudFront caches objects at edge locations based on TTL settings. Without a cache invalidation request, users continue to receive the old cached content until the TTL expires or the cache is manually cleared.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The website is served through Amazon CloudFront, and the CloudFront distribution cache was not invalidated after the deployment.
Why this is correct
Although CodePipeline updates the S3 origin with the new static files, CloudFront edge locations continue to serve stale content until the cache TTL expires or an explicit invalidation is submitted. A CloudFront distribution does not automatically detect origin content changes; it caches objects based on the Cache-Control/Expires headers. Without creating an invalidation for '/*' (or for the changed paths) after the deployment, users will still see the previous version of the website, which matches the reported symptom. This is the only option that explains outdated content being served while the pipeline itself succeeds.
- ✗
The S3 bucket policy blocks public read access, so users get a 403 error.
Why it's wrong here
If the S3 bucket policy blocks public read access, any request for the objects would receive an HTTP 403 Access Denied error, not an old version of the page. The symptom described is stale content being displayed, meaning the objects are still accessible but are not the newest files. Moreover, if CloudFront uses Origin Access Control (OAC), the distribution can read from a private S3 bucket regardless of the public bucket policy, so this would not even block CloudFront. Therefore, a bucket policy issue would produce an availability failure rather than the observed cache-related staleness.
- ✗
The IAM role for CodeBuild does not have permissions to write to the S3 bucket.
Why it's wrong here
If the CodeBuild IAM role lacked permission to write to the S3 bucket, the deploy action would fail because the pipeline could not upload the built artifacts. That would halt the pipeline in the deploy stage, and CloudFront would not serve any new content — but users would see the old content while the pipeline status shows a failure. Since the question implies the deployment completes and users are still seeing outdated files, a permissions failure is incompatible with the scenario. Insufficient write permissions cause an error during deployment, not a silent stale-content delivery after a successful deployment.
- ✗
The deploy stage uses 's3 cp' instead of 's3 sync', so new files are not uploaded.
Why it's wrong here
The scenario explicitly states the deploy stage uses 's3 sync' to upload the site content, so the premise of this option is false. Even if 's3 cp' were used, both commands upload files from the local build output to S3; 'cp' copies all files each time, while 'sync' copies only new or changed files. Either way, the S3 bucket would contain the latest files, and the problem would still lie downstream in CloudFront's cache. Therefore, this option misidentifies the upload mechanism and cannot account for users receiving outdated content.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.