DOP-C02 SDLC Automation Practice Question
A company wants to ensure that all code changes are reviewed before being merged to the main branch in AWS CodeCommit. Which feature should be enabled?
⚠ Common exam trap
The trap here is that candidates familiar with GitHub or GitLab mistakenly expect 'branch protection rules' (Option B) to exist in CodeCommit, but AWS CodeCommit requires approval rule templates instead, and the exam tests this platform-specific difference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an approval rule template and associate it with the main branch.
AWS CodeCommit does not natively support branch protection rules like GitHub or GitLab. Instead, you must create an approval rule template and associate it with the main branch to require at least one approved pull request before merging. This ensures all code changes are reviewed before being merged to the main branch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Lambda function to validate commits and block pushes.
Why it's wrong here
AWS CodeCommit does not support pre-receive hooks that can intercept and block a push before it is accepted. A Lambda function can be invoked asynchronously by repository events such as push creation via EventBridge, but it only reacts after the fact and cannot force an update to be rejected. Therefore, this approach cannot guarantee that all changes are reviewed before they enter the main branch.
- ✗
Enable branch protection rules on the repository.
Why it's wrong here
CodeCommit lacks the branch protection rules feature found in GitHub and GitLab; there is no built-in setting to prevent direct pushes to a branch. While you can restrict permissions with IAM policies, those policies control who can push, not whether a review has occurred. The native mechanism to require human review on merges is the approval rules feature tied to pull requests.
- ✓
Create an approval rule template and associate it with the main branch.
Why this is correct
Create an approval rule template and associate it with the main branch to require one or more approved reviews before a pull request can be merged. The template can specify a minimum number of approvals and restrict which IAM principals can approve, and it applies automatically to every pull request targeting that branch. This is the only option that actually enforces the review gate as part of the merge workflow.
- ✗
Use CloudWatch Events to notify when a push occurs.
Why it's wrong here
Using CloudWatch Events (now Amazon EventBridge) to trigger a notification when a push occurs is an event-driven alerting mechanism, not an enforcement control. It can send an SNS email or invoke a Lambda for monitoring, but it does not prevent the push or block an unapproved merge. Thus, it improves visibility but cannot ensure that code changes are reviewed prior to being committed to the repository.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.