S3 Event Notification Filter Causing CodePipeline Not to Trigger
A company uses AWS CodePipeline with a source stage from Amazon S3. The pipeline triggers on changes to the S3 bucket. However, the pipeline does not trigger when a new object is uploaded. What is the MOST likely cause?
⚠ Common exam trap
It's easy for candidates to assume CodePipeline automatically polls S3 for changes (like GitHub webhooks), but in reality, S3 requires an explicit event notification configuration to trigger the pipeline, and the exam tests this distinction between polling-based and event-driven triggers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket does not have an event notification configured to invoke the pipeline.
CodePipeline does not automatically monitor S3 buckets for new objects. To trigger a pipeline on S3 events, you must explicitly configure an S3 event notification (e.g., s3:ObjectCreated:Put) that sends the event to CloudWatch Events or directly to CodePipeline via Amazon EventBridge. Without this notification, the pipeline will not start when a new object is uploaded.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The S3 bucket policy denies the CodePipeline service role.
Why it's wrong here
A bucket policy that denies the CodePipeline service role would result in AccessDenied errors when the pipeline attempts to list or read objects from the source bucket. However, this condition affects the actual execution of the source action, not the initial trigger that starts the pipeline. Since the symptom is that the pipeline never starts automatically, the missing event notification is the root cause, not an authorization failure.
- ✗
The S3 bucket is in a different AWS Region than the pipeline.
Why it's wrong here
CodePipeline fully supports cross-region pipelines and source buckets located in a different AWS Region. You would only need to configure a cross-region source action or replicate the bucket to the pipeline's region for execution. A geographic mismatch would not prevent the pipeline from being triggered by an S3 event; instead, it might cause latency or require additional setup. Therefore, the issue described is unrelated to regional configuration.
- ✗
The S3 bucket does not have versioning enabled.
Why it's wrong here
Versioning must indeed be enabled for any S3 bucket used as a source in CodePipeline, but this is required for tracking object revisions, not for sending event notifications. If versioning were disabled, the pipeline would fail when it attempts to retrieve the source artifact, or it might not even pass validation during setup. The lack of versioning would not stop the S3 event notification from firing and invoking the pipeline, so the pipeline would still start and then error.
- ✓
The S3 bucket does not have an event notification configured to invoke the pipeline.
Why this is correct
CodePipeline automatically starts an S3 source only when the bucket is configured with an event notification that sends object-created events to the pipeline's trigger. Typically, this is implemented via an Amazon S3 event notification targeting an Amazon EventBridge rule, or via a CloudWatch Events rule that filters on the bucket's PUT operations. Without that configuration, uploading a new file to the bucket does not cause the pipeline to initiate, leaving it in a 'Succeeded' or previous state until a manual release is triggered. This exactly matches the reported symptom.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.