DOP-C02 SDLC Automation Practice Question
A DevOps engineer is designing a CI/CD pipeline for a serverless application using AWS Lambda. They want to automatically deploy the latest version of the Lambda function to production after running integration tests. The source code is in AWS CodeCommit. Which pipeline configuration should they use?
⚠ Common exam trap
Candidates often assume any pipeline that runs tests before deploying to Lambda is sufficient, but the exam specifically tests the need for managed deployment strategies (CodeDeploy) over direct API calls or CLI commands to ensure production safety and rollback capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CodeCommit -> CodeBuild (test) -> CodeDeploy (Lambda deployment) -> Lambda.
It uses CodeDeploy's built-in Lambda deployment support, which enables safe, gradual traffic shifting (e.g., canary or linear deployments) and automatic rollback on CloudWatch alarm failures. This pipeline integrates CodeCommit for source, CodeBuild for integration tests, and CodeDeploy to orchestrate the Lambda update with minimal risk, aligning with AWS best practices for serverless CI/CD.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CodeCommit -> CodeBuild (test) -> CodeDeploy (Lambda deployment) -> Lambda.
Why this is correct
This is correct because CodeDeploy natively supports Lambda deployment with canary, linear, and all-at-once traffic-shifting strategies, letting you validate a new version before promoting it. CodeBuild runs automated tests first, then CodeDeploy updates the Lambda alias gradually, monitoring CloudWatch alarms for automatic rollback. This is the AWS-recommended managed deployment path for serverless applications.
- ✗
CodeCommit -> CodeBuild (test) -> Lambda (deploy via update-function-code).
Why it's wrong here
Directly invoking update-function-code from the test stage publishes a new Lambda version immediately to $LATEST or a fixed alias, but it provides no traffic shifting, no staged rollout, and no automatic rollback on CloudWatch alarm failures. It is an imperative single-step action, not a managed deployment strategy, so a bad deploy can affect 100% of production traffic instantly. CodeDeploy is designed to coordinate safe Lambda releases with version/alias routing.
- ✗
CodeCommit -> Lambda (deploy via S3 trigger) -> CodeBuild (test) -> production.
Why it's wrong here
This pipeline deploys to Lambda via an S3-triggered function before tests run, meaning untested code is promoted to production and can impact users immediately; any regression is discovered only after the fact, making rollback painful. The S3 trigger is an event-driven invocation pattern, not a deployment service, so it lacks deployment strategies, traffic shifting, and the ability to automate rollbacks. Tests must always gate promotion, not run after.
- ✗
CodeCommit -> CodeBuild (test and deploy) -> Lambda via AWS CLI in buildspec.
Why it's wrong here
Executing the AWS CLI inside a buildspec for both build and deploy merges concerns and requires embedding explicit CLI commands that are harder to audit and control than CodePipeline/CodeDeploy actions. This approach typically relies on long-lived IAM access keys or overly broad permissions in the CodeBuild service role, increasing security risk, and it omits CodeDeploy's managed features like rollback triggers, deployment health, and execution history. It is less secure, less traceable, and less reproducible.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.