Courseiva
SDLC Automation →hardMultiple Select

DOP-C02 SDLC Automation Practice Question

A company uses AWS CodePipeline with multiple stages: Source (CodeCommit), Build (CodeBuild), Test (CodeBuild), and Deploy (CodeDeploy to EC2). The Test stage runs integration tests that require network access to a private database in a VPC. The CodeBuild project is configured to use a VPC. However, the Test stage fails intermittently with timeout errors. Which TWO actions would MOST likely resolve the issue? (Choose 2)

⚠ Common exam trap

The trap here is that candidates may focus on security group rules (Option E) as the primary fix, but the intermittent nature of the timeout points to network path delays or missing NAT gateway, not a static misconfiguration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the timeout for the Test stage in the CodeBuild project to accommodate network delays.

The intermittent timeout errors suggest that the Test stage's integration tests are occasionally taking longer than the configured timeout. Increasing the timeout accommodates these delays, preventing premature failures. Option C is correct because a NAT gateway is required for CodeBuild in a VPC to access resources outside the VPC, such as the private database, if the database is in a different subnet or requires internet-routable traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the VPC configuration from the CodeBuild project and use a public subnet instead.

    Why it's wrong here

    Removing the VPC configuration from the CodeBuild project and using a public subnet would break access to the private database entirely. CodeBuild builds that run in a VPC have elastic network interfaces attached to a private subnet; without that VPC attachment, the build environment only has internet access via the CodeBuild service's own network, and cannot route to resources inside your VPC. A public subnet is also not the correct fix—the database should remain in a private subnet, and the issue is intermittent timeout, not a fundamental lack of connectivity.

  • ✓

    Increase the timeout for the Test stage in the CodeBuild project to accommodate network delays.

    Why this is correct

    Increasing the Test stage timeout in the CodeBuild project is a pragmatic mitigation when network congestion intermittently causes dependencies or database connections to be slower than the default limit. CodeBuild has a default timeout of 60 minutes for a build, but the pipeline's stage timeout may be shorter, and network retries during peak usage can push a stage over its configured limit without an underlying configuration error. This accommodates transient network delays rather than masking a permanent misconfiguration, making it a valid, if not root-cause, fix.

  • ✓

    Ensure the CodeBuild project's VPC configuration includes a NAT gateway for internet access.

    Why this is correct

    If the database or other test dependencies require internet access—for example, to fetch external test libraries, call third-party APIs, or validate certificates—the CodeBuild project must be able to route outbound traffic from the private subnet. A NAT gateway in the VPC enables outbound internet connectivity for resources in private subnets, which is a common and correct configuration for a CodeBuild project attached to a VPC. Without a NAT gateway, the build environment can reach the database via the private subnet but cannot reach the internet, leading to timeouts when external resources are accessed.

  • ✗

    Use a larger compute type for the CodeBuild project to improve network performance.

    Why it's wrong here

    Choosing a larger compute type for the CodeBuild project increases vCPU and memory for the build, which can speed up CPU-bound tasks like test execution, but it does not directly affect network latency, packet loss, or the ability to reach an endpoint. Intermittent timeout errors are typically caused by network-level issues—security group rules, route tables, NAT availability, or transient congestion—not by insufficient compute capacity. A bigger instance does not improve the round-trip time to the database or fix the underlying connectivity path, so this change would leave the timeout problem unresolved.

  • ✗

    Configure the security group for the CodeBuild project to allow outbound traffic to the database security group on the required port.

    Why it's wrong here

    This security group rule is a necessary prerequisite for the CodeBuild project to communicate with the database, but the question states the database access is already working (the error is intermittent). If the security group were misconfigured, the tests would fail consistently, not occasionally. Intermittent timeouts suggest a different layer of the network path—such as a NAT gateway going down, a route table issue, or a database throttling event—so merely ensuring outbound traffic to the database port is correct is not a targeted fix for the stated symptom.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.