DOP-C02 SDLC Automation Practice Question
A company uses AWS CodePipeline with a source stage from Amazon S3 and a deploy stage to AWS Elastic Beanstalk. The pipeline has been working for months, but recently the deploy stage started failing with the error 'The S3 object does not exist.' The source artifact is uploaded to the S3 bucket by an external system. Which TWO actions should be taken to resolve this issue? (Choose TWO.)
⚠ Common exam trap
Many candidates assume the error is due to a permission or encryption issue (like SSE-KMS) rather than recognizing it as a classic race condition caused by object overwriting in a non-versioned bucket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the external system does not overwrite the object after the pipeline execution starts.
The deploy stage fails with 'The S3 object does not exist' when the external system overwrites the source artifact after the pipeline execution starts. CodePipeline references the object by its key at the time the pipeline is triggered; if the object is replaced (i.e., deleted and re-uploaded with the same key), the pipeline may attempt to download a version that no longer exists, especially if the S3 bucket is not versioned. Ensuring the external system does not overwrite the object during execution prevents this race condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure the external system does not overwrite the object after the pipeline execution starts.
Why this is correct
CodePipeline's S3 source action resolves the artifact by object key at the moment the pipeline execution starts. If an external system overwrites or deletes that object during the run, the pipeline may fetch a different revision or fail entirely because the original content no longer exists. Enforcing immutability through a write-once policy or access controls prevents this race condition and guarantees the pipeline operates on a stable artifact.
- ✗
Change the source stage to use AWS CodeCommit instead of S3.
Why it's wrong here
Switching to CodeCommit is unnecessary and shifts the architecture rather than fixing the actual defect. CodeCommit also tracks branch tips, and if a commit is force-pushed or a branch is updated, similar consistency concerns can arise. The problem is the external system mutating the S3 object, not the source repository type, so this change does not address the root cause and introduces migration overhead.
- ✓
Enable versioning on the S3 bucket and configure the pipeline to use the specific version ID.
Why this is correct
Enabling S3 versioning preserves every upload as a distinct version ID, and CodePipeline's S3 source action can be configured to use a specific version ID via the S3ObjectVersion field. This lets the pipeline download the exact immutable object revision even if the external system later overwrites the same key. Without specifying the version ID, the pipeline would still pick the latest version, so this configuration must be explicitly set to provide deterministic builds.
- ✗
Use server-side encryption with AWS KMS (SSE-KMS) on the S3 bucket.
Why it's wrong here
SSE-KMS encrypts object data at rest and for transit, but it does not prevent overwrites or deletions. CodePipeline can decrypt objects if the pipeline role has kms:Decrypt permission, and encryption does not make an object immutable. The failure here is caused by the object being replaced or removed, not by an encryption or access issue, so KMS is unrelated to the root cause.
- ✗
Increase the timeout for the deploy stage in the pipeline.
Why it's wrong here
Increasing the deploy stage timeout only extends how long CodePipeline waits for deployment actions to complete; it cannot resurrect a missing or overwritten source object. The failure occurs in the source stage when the artifact cannot be fetched, so the deploy stage never receives valid input. This adjustment masks symptoms and wastes pipeline time without addressing the S3 object lifecycle problem.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.