Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company uses AWS CodePipeline to deploy applications. The pipeline must deploy to an Amazon ECS cluster. The security team requires that all deployment actions be logged and auditable. Which configuration should be used?

⚠ Common exam trap

DOP-C02 often tests the difference between operational logging (CloudWatch Logs, which shows pipeline execution details) and security auditing (CloudTrail, which records API calls with identity and source) — candidates frequently pick CloudWatch Logs because it sounds like it covers 'logging,' but it lacks the audit-level detail required for security compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail to record all API calls made by CodePipeline.

AWS CloudTrail records all API calls made to AWS services, including those made by CodePipeline when it invokes ECS deployment actions (such as UpdateService, RegisterTaskDefinition, or CreateDeployment). Enabling CloudTrail provides the audit trail required by the security team, capturing who made the call, when, from where, and what the request contained.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable VPC Flow Logs for the ECS cluster's VPC.

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata at the network interface level, not the deployment actions—such as pipeline stage transitions, task definition updates, or service modifications—that the security team requires to be logged and auditable. This option is tempting because VPC Flow Logs do provide an audit trail for network traffic, which would be correct if the requirement were to log all network-level communication to and from the ECS cluster, rather than the deployment operations themselves.

  • ✗

    Enable Amazon S3 server access logs for the artifact bucket used by CodePipeline.

    Why it's wrong here

    Amazon S3 server access logs record object-level requests made to the artifact bucket, such as PutObject, GetObject, and ListBucket operations. They do not capture the logical execution of a pipeline, including stage transitions, approval actions, or the deployment actions that CodePipeline performs on the target environment. Therefore, enabling them would not give the security team the audit trail of deployment operations they require.

  • ✓

    Enable AWS CloudTrail to record all API calls made by CodePipeline.

    Why this is correct

    AWS CloudTrail is the native audit service that records all API calls made by or on behalf of CodePipeline, including pipeline creation, stage updates, and StartPipelineExecution. Each event includes the identity of the caller, the time of the call, the source IP, and the request parameters, providing a complete and tamper-evident audit trail. This directly satisfies the requirement to log and audit deployment actions, making it the correct choice.

  • ✗

    Enable Amazon CloudWatch Logs for the CodePipeline.

    Why it's wrong here

    Amazon CloudWatch Logs is designed to collect, monitor, and store log output generated by applications, such as container stdout/stderr or server access logs, not to record the history of API calls or pipeline execution events. CodePipeline does not write its execution history to CloudWatch Logs by default; pipeline state changes are available in the console and via APIs, but for a durable, queryable audit trail, you need CloudTrail. Therefore, enabling CloudWatch Logs for CodePipeline alone would not capture the deployment actions the security team wants to audit.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.