Courseiva
Security and Compliance →hardMultiple Choice

Encrypt CodePipeline Artifacts at Rest and In Transit

A company uses AWS CodePipeline to deploy a web application to an Auto Scaling group. The security team requires that all artifacts in the pipeline be encrypted at rest. The pipeline uses an S3 bucket as the artifact store. Which combination of actions should the DevOps engineer take to meet this requirement with minimal operational overhead?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 default encryption with SSE-S3 on the artifact bucket.

Enabling S3 default encryption with SSE-S3 on the artifact bucket is the simplest way to encrypt all objects at rest with minimal operational overhead. SSES3 uses S3-managed keys, requiring no additional key management or permissions. Option A is wrong because AWS Certificate Manager provides TLS certificates, not encryption for S3 objects. Option C is wrong because using a Lambda function to encrypt artifacts after each stage adds unnecessary complexity and does not automatically encrypt all artifacts, especially existing ones. Option D is wrong because creating a customer-managed KMS key introduces additional overhead for key management and permissions, which is not minimal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Certificate Manager to encrypt the artifacts.

    Why it's wrong here

    AWS Certificate Manager (ACM) provisions and renews TLS/SSL certificates for use with CloudFront, ALB/NLB, and API Gateway; it does not encrypt data at rest in S3. S3 artifact encryption is managed by S3 server-side encryption keys, not by certificate authorities or TLS. Therefore, ACM cannot apply any encryption to pipeline artifact buckets.

  • ✓

    Enable S3 default encryption with SSE-S3 on the artifact bucket.

    Why this is correct

    Enabling S3 default encryption with SSE-S3 on the CodePipeline artifact bucket automatically encrypts every object with 256-bit AES keys managed by Amazon S3. This is the simplest native approach: once enabled, you need no key management, no pipeline role changes, and no application code modifications. CodePipeline writes artifacts as normal S3 PUTs, so the bucket-level default encryption covers all stages and runs with zero overhead.

  • ✗

    Use an AWS Lambda function to encrypt artifacts after each pipeline stage.

    Why it's wrong here

    Invoking a Lambda function after every pipeline stage to encrypt artifacts introduces custom actions that are not native to CodePipeline's execution model, requiring Lambda permissions, S3 event logic, and re-uploading of transformed artifacts. More critically, artifacts exist unencrypted in S3 until the function runs, so this method does not guarantee encryption at rest for the duration of the pipeline. It adds latency, cost, and failure points compared with enabling S3 default encryption.

  • ✗

    Create a customer-managed KMS key and configure the pipeline to use it for artifact encryption.

    Why it's wrong here

    A customer-managed AWS KMS key is a viable server-side encryption option, but it adds operational burden: you must create the key, configure key policies, and grant CodePipeline's service role permissions for kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey. You also need to audit key usage and plan for key rotation and possible re-encryption. Because S3's built-in SSE-S3 offers equivalent at-rest protection without these responsibilities, the KMS option is not the most efficient solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.