Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer is designing a CI/CD pipeline that deploys to production. The security team mandates that all code changes must be reviewed and signed off by two senior developers before deployment. How can this be enforced?

⚠ Common exam trap

A common mix-up: candidates confuse deployment-stage approvals (like CodePipeline manual approval) with pre-merge code review approvals, failing to recognize that the security requirement must be enforced at the source code repository level before the pipeline even starts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up a pull request approval rule in CodeCommit requiring two approvals.

CodeCommit's pull request approval rules allow you to require a specific number of approvals before a pull request can be merged. By configuring an approval rule template that requires two approvals from senior developers, you enforce the mandatory code review and sign-off before any change is merged into the production branch, which then triggers the CI/CD pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use CloudWatch Events to trigger a manual approval step in CodePipeline.

    Why it's wrong here

    CloudWatch Events (Amazon EventBridge) can trigger a CodePipeline action, but a manual approval action in CodePipeline is a single sign-off gate, not a two-person review. Even if you configure the pipeline to stop at an approval stage, the approver is typically one IAM principal, and CloudWatch Events cannot enforce that two distinct users approve. The mechanism also does not integrate with the code review process in CodeCommit; it only gates deployment after a commit is already merged, so it fails to prevent unreviewed code from entering the repository.

  • ✗

    Restrict push access to the production branch to only the two senior developers.

    Why it's wrong here

    Restricting push access to only the two senior developers limits who can write to the production branch, but it does not implement a mandatory code review workflow. Those two developers could still push directly to the branch without any peer review, and a single compromised credential or malicious actor with one of those IAM permissions could push unreviewed changes. This is an authorization control, not an approval control, and does not satisfy a compliance requirement for two-person approval on every change.

  • ✗

    Use AWS Lambda to send a notification when a change is pushed.

    Why it's wrong here

    A Lambda function that publishes a notification (e.g., via SNS or Slack) when a push occurs only informs stakeholders after the fact; it provides no mechanism to block or approve the change. Notifications are event-driven side effects and have no integration with CodeCommit's pull request workflow, so they cannot enforce a policy requiring two approvals before a merge. This option confuses observability with governance and would not prevent unreviewed or unapproved commits from being deployed.

  • ✓

    Set up a pull request approval rule in CodeCommit requiring two approvals.

    Why this is correct

    Setting up a pull request approval rule in CodeCommit requires at least two approvals from IAM principals (other than the commit author) before the pull request can be merged. This is a native CodeCommit feature that enforces the two-person review rule at the source, allowing the pipeline to deploy only code that has passed the mandated review process. The approval rule can also be associated with the repository's target branch (e.g., production) and automatically applies to all PRs targeting that branch, making it the correct control to meet the requirement.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.