Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A development team uses AWS CodePipeline with multiple stages including source, build, and deploy. The pipeline uses an Amazon S3 source action that triggers on changes to a specific bucket. Recently, the pipeline stopped triggering automatically. The IAM role for CodePipeline has the necessary permissions. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume S3 event notifications are required for CodePipeline triggers, but AWS actually uses CloudTrail and EventBridge, so the correct answer focuses on CloudTrail configuration rather than S3 notifications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail is not configured to deliver S3 data events to CloudWatch Logs.

CodePipeline's S3 source action does not rely on S3 event notifications to trigger pipeline executions. Instead, it uses Amazon CloudWatch Events (now Amazon EventBridge) to detect changes to the S3 bucket. For this to work, AWS CloudTrail must be configured to deliver S3 data events (specifically `PutObject` API calls) to CloudWatch Logs, which then generates the event that triggers the pipeline. Without CloudTrail data event logging, CodePipeline cannot detect object uploads, even if the IAM role has proper permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM role for CodePipeline does not have s3:GetObject permission.

    Why it's wrong here

    The pipeline's IAM role is provisioned with the required S3 access as part of the stated setup. CodePipeline uses its service role to retrieve input artifacts from the source bucket, and a missing s3:GetObject permission would manifest as an 'Access Denied' error during the Source or DownloadArtifact stage. Since the pipeline is configured with a valid role and policy, this is not the root cause; the failure lies in the event trigger mechanism.

  • ✗

    The S3 bucket policy denies access to CodePipeline.

    Why it's wrong here

    An S3 bucket policy that denies CodePipeline access would explicitly block the service's ability to read source artifacts, causing retrieval failures. However, in this scenario the bucket policy is permissive and does not contain any Deny statement targeting CodePipeline or its role. More importantly, the failure is not about reading objects but about the event detection that triggers the pipeline, which is governed by CloudWatch Events and CloudTrail, not by bucket-level access controls.

  • ✗

    The S3 bucket does not have event notifications configured.

    Why it's wrong here

    S3 event notifications are an independent feature used to route object-created events to Lambda, SQS, or SNS; CodePipeline does not consume them for its source triggers. Instead, CodePipeline relies on Amazon CloudWatch Events (now Amazon EventBridge) rules to detect s3:ObjectCreated events by analyzing CloudTrail logs. Therefore, the mere absence of S3 event notifications has no impact on pipeline triggering.

  • ✓

    AWS CloudTrail is not configured to deliver S3 data events to CloudWatch Logs.

    Why this is correct

    CodePipeline uses Amazon EventBridge rules that match S3 object-created events recorded by AWS CloudTrail as data events. For these events to reach EventBridge, CloudTrail must be enabled to log S3 data events for the source bucket and deliver them to a CloudWatch Logs log group; the EventBridge rule then forwards matching events to the pipeline. If CloudTrail is not configured to deliver S3 data events to CloudWatch Logs, the pipeline's trigger remains silent even though the source code changes, causing the pipeline to appear stalled or never start. This is the root cause, as the IAM role, bucket policy, and S3 event notifications are all in order.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.