Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

Exhibit

Refer to the exhibit.
```
Starting build...
[Container] 2024/01/15 10:00:00 Phase complete: DOWNLOAD_SOURCE State: FAILED
[Container] 2024/01/15 10:00:00 Phase context status code: COMMAND_EXECUTION_ERROR Message: Error while executing command: git fetch origin +refs/pull/*:refs/remotes/origin/pr/*. Reason: exit status 128
```

A developer is troubleshooting a failed CodeBuild build. The build is triggered by a pull request from a forked repository. The buildspec includes a command to fetch pull request references. What is the most likely cause of the failure?

⚠ Common exam trap

A common mix-up: candidates assume the failure is due to IAM permissions or buildspec issues, overlooking the specific CodeBuild setting that controls whether pull requests from forked repositories are allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CodeBuild project is not configured to allow pull requests from forked repositories.

When a build is triggered by a pull request from a forked repository, CodeBuild requires explicit configuration to allow builds from forks. By default, CodeBuild projects do not accept webhook events from forked repositories. The error occurs because the project lacks the 'Allow pull requests from forked repositories' setting enabled, even though the IAM role and buildspec may be correctly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM role for CodeBuild does not have permission to read from the repository.

    Why it's wrong here

    A CodeBuild project's IAM service role controls access to AWS resources such as S3, ECR, and CodeCommit, but for GitHub and GitHub Enterprise sources, authentication is handled by an OAuth token or GitHub App credentials, not the IAM role. Even if the role lacked permissions for the source, the failure would occur in the DOWNLOAD_SOURCE phase with an access-denied error before any git refs are fetched. A git-fetch failure specifically points to the repository/ref resolution logic, not to IAM authorization.

  • ✗

    The buildspec file is not present in the source code.

    Why it's wrong here

    A missing buildspec file prevents the build from entering the command-execution phases; CodeBuild reports a BUILD_SPEC_NOT_FOUND or invalid buildspec error during the DOWNLOAD_SOURCE phase, after source is retrieved but before parsing the refs. Because the failure in this scenario occurs during git fetch, the source has already been discovered and CodeBuild is attempting to resolve the pull request's head or merge ref. Thus the absence of a buildspec is not the cause of this fetch-stage error.

  • ✓

    The CodeBuild project is not configured to allow pull requests from forked repositories.

    Why this is correct

    CodeBuild intentionally does not build pull requests from forked repositories unless you explicitly enable the 'Allow pull requests from forked repositories' setting in the project's webhook configuration. Fork PRs are considered untrusted because the entire buildspec, including install commands and environment variable injection, is controlled by the fork author—so CodeBuild requires an opt-in before it will fetch refs such as refs/pull/123/head or refs/pull/123/merge from a fork. When this setting is off, the source client cannot complete the git fetch for the fork PR, producing exactly the kind of git error being troubleshooted.

  • ✗

    The buildspec contains invalid syntax.

    Why it's wrong here

    If the buildspec contained invalid YAML or JSON syntax, the error would surface after CodeBuild downloads the source and attempts to parse the buildspec—typically as a CLIENT_ERROR with a message like 'Invalid buildspec file' and a line/column reference. Those parsing errors occur in the DOWNLOAD_SOURCE or BUILD phase, not while running git fetch. Because the failure described is during git fetch, CodeBuild has not yet reached the buildspec evaluation stage, so invalid syntax cannot be the cause.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.