DOP-C02 SDLC Automation Practice Question
A developer wants to automatically deploy a new version of an AWS Lambda function whenever code is pushed to a specific branch in AWS CodeCommit. Which combination of services should be used?
⚠ Common exam trap
Test-takers frequently think a direct Lambda trigger from CodeCommit (via S3 or CloudWatch Logs) is sufficient, but they overlook the need for a pipeline service like CodePipeline to manage the deployment workflow and handle versioning, rollbacks, and approvals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CodeCommit, Amazon EventBridge, AWS CodePipeline
AWS CodePipeline can be configured with a source stage that uses AWS CodeCommit as the source provider, and an Amazon EventBridge rule can detect push events to a specific branch in CodeCommit. When a push occurs, EventBridge triggers the pipeline execution, which then deploys the new Lambda function version automatically. This combination provides a fully managed, event-driven CI/CD pipeline for Lambda deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CodeCommit, Amazon EventBridge, AWS CodePipeline
Why this is correct
CodeCommit pushes are natively captured as events by Amazon EventBridge, which can be configured with a rule that matches the `codecommit:Push` event on a branch. That rule targets an AWS CodePipeline execution, and CodePipeline's deploy stage updates the Lambda function using either a CloudFormation stack or an AWS Lambda deploy action. This gives a fully managed, event-driven CI/CD workflow with no custom glue code, no polling, and no intermediate storage.
- ✗
AWS CodeCommit, Amazon S3, AWS Lambda
Why it's wrong here
S3 is an unnecessary middleman because CodePipeline can consume CodeCommit as its source directly; introducing S3 adds object copying and versioning complexity without enabling any new capability. If you instead use Lambda to respond to CodeCommit events, you'd be hand-rolling the deployment pipeline inside a single function, losing CodePipeline's stage-based orchestration, manual approval hooks, and rollback visibility. The described trio is a fragile workaround, not a durable CI/CD architecture.
- ✗
AWS CodeCommit, AWS CodeBuild
Why it's wrong here
CodeBuild is a build service that compiles and tests source code, but it has no native Lambda deployment action; any `aws lambda update-function-code` call would be a custom shell script inside a buildspec, bypassing the CD layer. Without CodePipeline there is no orchestration between source changes and subsequent environments, and you'd also lose automated rollback, integration with CodeDeploy traffic shifting, and detailed pipeline execution history. Therefore, CodeCommit plus CodeBuild alone cannot automatically deploy a new version; it only builds.
- ✗
AWS CodeCommit, Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs is a destination for operational logs and metrics, not a trigger mechanism for cloud resources. It cannot subscribe to CodeCommit repository change events; only EventBridge can capture and route those events to a target like CodePipeline. Even if you sent CodeCommit activity to CloudWatch Logs via other means, Logs has no means to execute deployment actions, so it cannot fulfill the deployment requirement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A team wants to automatically deploy a new version of a Lambda function when code is pushed to a CodeCommit repository. Which AWS service should orchestrate this workflow?
easy- A.AWS CodeDeploy
- B.AWS CodeBuild
- ✓ C.AWS CodePipeline
- D.AWS CloudFormation
Why C: AWS CodePipeline is the correct service because it is a fully managed continuous delivery service that orchestrates the entire release process, including source code changes from CodeCommit, building with CodeBuild, and deploying to Lambda. It can automatically trigger a pipeline execution when a new commit is pushed to a CodeCommit repository, enabling automated deployment of the Lambda function.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.