DOP-C02 SDLC Automation Practice Question
A development team uses AWS CodePipeline with multiple stages including source, build, and deploy. The pipeline uses an Amazon S3 source action that triggers on changes to a specific bucket. Recently, the pipeline stopped triggering automatically. The IAM role for CodePipeline has the necessary permissions. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume S3 event notifications are required for CodePipeline triggers, but AWS actually uses CloudTrail and EventBridge, so the correct answer focuses on CloudTrail configuration rather than S3 notifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail is not configured to deliver S3 data events to CloudWatch Logs.
CodePipeline's S3 source action does not rely on S3 event notifications to trigger pipeline executions. Instead, it uses Amazon CloudWatch Events (now Amazon EventBridge) to detect changes to the S3 bucket. For this to work, AWS CloudTrail must be configured to deliver S3 data events (specifically `PutObject` API calls) to CloudWatch Logs, which then generates the event that triggers the pipeline. Without CloudTrail data event logging, CodePipeline cannot detect object uploads, even if the IAM role has proper permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM role for CodePipeline does not have s3:GetObject permission.
Why it's wrong here
The pipeline's IAM role is provisioned with the required S3 access as part of the stated setup. CodePipeline uses its service role to retrieve input artifacts from the source bucket, and a missing s3:GetObject permission would manifest as an 'Access Denied' error during the Source or DownloadArtifact stage. Since the pipeline is configured with a valid role and policy, this is not the root cause; the failure lies in the event trigger mechanism.
- ✗
The S3 bucket policy denies access to CodePipeline.
Why it's wrong here
An S3 bucket policy that denies CodePipeline access would explicitly block the service's ability to read source artifacts, causing retrieval failures. However, in this scenario the bucket policy is permissive and does not contain any Deny statement targeting CodePipeline or its role. More importantly, the failure is not about reading objects but about the event detection that triggers the pipeline, which is governed by CloudWatch Events and CloudTrail, not by bucket-level access controls.
- ✗
The S3 bucket does not have event notifications configured.
Why it's wrong here
S3 event notifications are an independent feature used to route object-created events to Lambda, SQS, or SNS; CodePipeline does not consume them for its source triggers. Instead, CodePipeline relies on Amazon CloudWatch Events (now Amazon EventBridge) rules to detect s3:ObjectCreated events by analyzing CloudTrail logs. Therefore, the mere absence of S3 event notifications has no impact on pipeline triggering.
- ✓
AWS CloudTrail is not configured to deliver S3 data events to CloudWatch Logs.
Why this is correct
CodePipeline uses Amazon EventBridge rules that match S3 object-created events recorded by AWS CloudTrail as data events. For these events to reach EventBridge, CloudTrail must be enabled to log S3 data events for the source bucket and deliver them to a CloudWatch Logs log group; the EventBridge rule then forwards matching events to the pipeline. If CloudTrail is not configured to deliver S3 data events to CloudWatch Logs, the pipeline's trigger remains silent even though the source code changes, causing the pipeline to appear stalled or never start. This is the root cause, as the IAM role, bucket policy, and S3 event notifications are all in order.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.