Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to ensure that infrastructure changes are reviewed and approved before deployment. The code is stored in AWS CodeCommit, and the pipeline uses AWS CodePipeline and AWS CloudFormation. What is the BEST way to implement an approval process for infrastructure changes?

⚠ Common exam trap

DOP-C02 often tests the distinction between repository-level controls (CodeCommit approval rules, pull requests) and pipeline-level controls (manual approval actions), so candidates who conflate 'code review' with 'deployment approval' pick Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a manual approval step in CodePipeline between the build and deploy stages.

A manual approval step in CodePipeline is the native, purpose-built mechanism for gating a pipeline stage on human review. CodePipeline pauses execution and sends an SNS notification to designated approvers; the pipeline resumes only after an approver acts in the console or via the API. This directly satisfies the requirement that infrastructure changes be reviewed and approved before CloudFormation deploys them, and it integrates cleanly with the existing CodeCommit/CodePipeline/CloudFormation toolchain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use CodeCommit approval rules to require a pull request before any change is merged.

    Why it's wrong here

    Use CodeCommit approval rules to require a pull request before any change is merged. This is incorrect because CodeCommit approval rules apply to pull requests for code changes, not to pipeline executions or infrastructure deployments.

  • ✗

    Configure IAM policies to require MFA before any CloudFormation stack update.

    Why it's wrong here

    Configure IAM policies to require MFA before any CloudFormation stack update. This is incorrect because IAM policies requiring MFA control who can update stacks, but do not create an approval gate; they enforce authentication, not approval workflows.

  • ✗

    Use CodeBuild to run a script that sends an approval request via Amazon SNS and waits for a response.

    Why it's wrong here

    A CodeBuild script sending an approval request via Amazon SNS and waiting for a response lacks native integration with CodePipeline’s manual approval action, meaning the pipeline cannot pause execution and resume only upon explicit approval; it would require custom polling logic and risk timeout failures. This approach is tempting because SNS is a standard notification service for alerting stakeholders, and in a non-pipeline context—such as triggering a manual review of a standalone deployment script—it would be a valid lightweight approval mechanism.

  • ✓

    Add a manual approval step in CodePipeline between the build and deploy stages.

    Why this is correct

    A manual approval action in CodePipeline is a first-class, natively integrated gate that pauses the pipeline execution at a defined stage boundary (e.g., after build, before deploy). When the action runs, CodePipeline sends an SNS notification to the designated approver topic, and the execution remains in a Waiting state until an authorized user explicitly approves or rejects it via the console, CLI, or SDK. This is the intended AWS pattern for a human review gate because it is fully managed, has no custom polling logic, and automatically resumes the pipeline only upon approval — making it superior to any ad-hoc script or external approval mechanism.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.