Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a critical application. Which security practice should the engineer implement to prevent unauthorized changes to the pipeline?

⚠ Common exam trap

DOP-C02 often tests the difference between preventive controls (IAM policies, SCPs) and detective controls (CloudTrail, SNS, CloudWatch) — candidates frequently pick logging/notification answers when the question asks how to prevent unauthorized changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM policy that uses a condition to allow only specific users or roles to modify the pipeline

The most direct preventive control is an IAM policy with a condition that restricts who can call CodePipeline mutation APIs (UpdatePipeline, DeletePipeline, PutApprovalResult, etc.). By scoping permissions to specific users or roles via IAM conditions (e.g., aws:PrincipalArn, aws:SourceVpce), the engineer enforces least privilege and blocks unauthorized modifications at the API layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypt the pipeline artifacts using AWS KMS

    Why it's wrong here

    Encrypting pipeline artifacts with AWS KMS protects the confidentiality and integrity of artifact data at rest and in transit, but it does nothing to control who can call CreatePipeline or UpdatePipeline. A malicious principal with valid IAM credentials could still alter the pipeline definition or replace the artifact source if they hold the required permissions. KMS encryption is a data-protection control, not an authorization control for the pipeline resource itself.

  • ✗

    Use SNS to send notifications when the pipeline is updated

    Why it's wrong here

    Sending an Amazon SNS notification when the pipeline is updated only alerts operators after a modification has already been accepted by the CodePipeline service. It provides no enforcement mechanism to stop unauthorized changes because SNS is a publish/subscribe messaging service, not an authorization service. Notification-based monitoring is useful for incident response but cannot serve as a preventive guardrail against pipeline tampering.

  • ✓

    Attach an IAM policy that uses a condition to allow only specific users or roles to modify the pipeline

    Why this is correct

    Attaching an IAM policy that uses a condition such as aws:PrincipalArn to the CodePipeline administrative actions (for example, UpdatePipeline and CreatePipeline) is the correct preventive control. This restricts the set of principals who can modify the pipeline definition no matter how the request is made, and it can be combined with resource-level permissions and least-privilege scoping. It directly addresses unauthorized pipeline modifications at the authorization layer.

  • ✗

    Enable AWS CloudTrail and create a CloudWatch Events rule to notify on pipeline changes

    Why it's wrong here

    Enabling CloudTrail to log pipeline API activity and creating a CloudWatch Events rule to notify on pipeline changes gives you a forensic record and an alert after the fact, but it does not deny or block the offending operation. CloudTrail records the action only after authorization and execution have already occurred, making it a purely detective control. It complements IAM-based protection but cannot replace it because it does not participate in the policy evaluation process.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.