DOP-C02 SDLC Automation Practice Question
A company uses AWS CodePipeline with a GitHub source action. The pipeline is configured to trigger on changes to the main branch. After a recent commit, the pipeline did not trigger. The DevOps engineer verified that the webhook is configured correctly and the IAM role has the necessary permissions. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates may focus on webhook configuration or IAM permissions, overlooking that the GitHub personal access token is a separate authentication mechanism that can expire independently of the webhook setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The GitHub personal access token used for authentication has expired.
The most likely cause is that the GitHub personal access token used for authentication has expired. CodePipeline uses this token to authenticate with GitHub and trigger the webhook; when the token expires, GitHub rejects the webhook call, preventing the pipeline from starting even though the webhook configuration and IAM permissions are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The GitHub personal access token used for authentication has expired.
Why this is correct
The PAT is the credential CodePipeline uses to authenticate to GitHub for API calls, including the initial webhook registration and every source-revision lookup (e.g., GetCommit, ListCommits). When the token expires, CodePipeline receives 401/403 responses, so webhook events cannot be processed successfully and the Source stage fails or is skipped, which matches the observed post-push behavior.
- ✗
The pipeline is set to manual execution only.
Why it's wrong here
A manual-execution-only pipeline would not have a GitHub webhook configured as the change-detection method; instead it would require a manual Release button. The pipeline is currently configured with a GitHub webhook trigger, and the engineer's troubleshooting focuses on why the Source stage did not run after a push — so the trigger mechanism was working, eliminating manual-only as the cause.
- ✗
The source action's branch filter is set to a different branch.
Why it's wrong here
The branch filter was explicitly verified by the engineer to be correct, and it actually matches the branch that was pushed. An incorrect branch filter would cause pushes to the target branch to be ignored at the event-trigger level, but it would not produce a failing source action or a broken source stage; since the pipeline's branch setting is confirmed correct, this option is ruled out.
- ✗
The GitHub webhook endpoint URL is incorrect.
Why it's wrong here
The webhook endpoint URL is automatically provisioned by CodePipeline and was confirmed to be correct. If the URL were wrong, GitHub's webhook delivery would fail entirely with a 502/404 before CodePipeline ever received the event, and the engineer would see failed deliveries in the GitHub repository's webhook settings — but the webhook configuration is intact.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.