Courseiva
SDLC Automation →mediumMultiple Select

DOP-C02 SDLC Automation Practice Question

A DevOps engineer is designing a CI/CD pipeline for a microservices architecture. The pipeline must ensure that only code that passes security scanning can proceed to deployment. Which TWO actions should the engineer take? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates confuse post-deployment monitoring (CloudWatch Events) with pre-deployment gating, or mistakenly think AWS CodeDeploy can perform security scanning, when in fact it only handles deployment orchestration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a security scanning stage in the pipeline after the build stage and before the deploy stage.

Integrating a security scanning stage after the build stage and before the deploy stage ensures that only code that has passed security checks proceeds to deployment. This aligns with the principle of shifting security left in the CI/CD pipeline, preventing vulnerable artifacts from reaching production environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon CloudWatch Events to trigger a rollback if vulnerabilities are found after deployment.

    Why it's wrong here

    Amazon CloudWatch Events (now Amazon EventBridge) can only react to externally generated findings after software is already live; it is not a security scanning service and does not prevent vulnerable code from reaching production. Detecting a vulnerability during runtime and then triggering a rollback means the exploit window is already open, which violates the shift-left security principle that gates artifacts before deployment. A rollback-driven response may also fail if the environment has been mutated by the vulnerability, so scanning must occur earlier in the pipeline.

  • ✓

    Add a security scanning stage in the pipeline after the build stage and before the deploy stage.

    Why this is correct

    Placing a security scanning stage immediately after the build stage and before the deploy stage makes the scan a quality gate on the immutable artifact itself, so deployment only proceeds when the artifact is clean. Tools like Amazon Inspector, Trivy, SonarQube, or Snyk can run in a CodeBuild action within CodePipeline to produce reports and block promotion. This 'shift-left' approach catches vulnerabilities while remediation is cheapest and before any environment is provisioned or exposed.

  • ✗

    Use AWS CodeDeploy to perform security scanning during deployment.

    Why it's wrong here

    AWS CodeDeploy is a deployment management service that orchestrates traffic shifts, rolling updates, and lifecycle hooks; it has no built-in security scanning capability. While you can add shell scripts to CodeDeploy lifecycle events, this is a custom workaround that runs only at deploy time, not an intrinsic scanner, and CodeDeploy's job is to place artifacts, not to validate their security. Relying on CodeDeploy for scanning conflates deployment orchestration with security enforcement and leaves no gate before artifacts are released.

  • ✗

    Configure the pipeline to run security scanning only in the deploy stage.

    Why it's wrong here

    Configuring the pipeline to run security scanning only in the deploy stage means every preceding stage—build, integration tests, and artifact promotion—has already accepted the vulnerable artifact, so the code can be exposed in lower or even production environments before the scan completes. Scanning during deployment also shares the deploy stage's lifecycle, so a scan failure causes a partially completed or aborted deployment that must be manually cleaned up. A dedicated stage before deploy, and independent of deployment mechanics, enforces a clean gate and avoids environment-side effects.

  • ✓

    Configure the pipeline to fail if the security scanning stage returns a non-zero exit code.

    Why this is correct

    Failing the pipeline when the security scanning stage returns a non-zero exit code transforms a passive report into an actionable gate: AWS CodePipeline marks the stage as Failed, stops downstream transitions, and triggers the configured failure actions. This is essential because a scan that only logs warnings without failing the build gives developers no enforcement mechanism, so high-severity vulnerabilities can be accidentally merged and deployed. Propagating the scanner's exit status to the CodePipeline action is a standard, robust way to ensure 'fail fast' behavior.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.