DOP-C02 Security and Compliance Practice Question
A DevOps engineer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a critical application. Which security practice should the engineer implement to prevent unauthorized changes to the pipeline?
⚠ Common exam trap
DOP-C02 often tests the difference between preventive controls (IAM policies, SCPs) and detective controls (CloudTrail, SNS, CloudWatch) — candidates frequently pick logging/notification answers when the question asks how to prevent unauthorized changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy that uses a condition to allow only specific users or roles to modify the pipeline
The most direct preventive control is an IAM policy with a condition that restricts who can call CodePipeline mutation APIs (UpdatePipeline, DeletePipeline, PutApprovalResult, etc.). By scoping permissions to specific users or roles via IAM conditions (e.g., aws:PrincipalArn, aws:SourceVpce), the engineer enforces least privilege and blocks unauthorized modifications at the API layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the pipeline artifacts using AWS KMS
Why it's wrong here
Encrypting pipeline artifacts with AWS KMS protects the confidentiality and integrity of artifact data at rest and in transit, but it does nothing to control who can call CreatePipeline or UpdatePipeline. A malicious principal with valid IAM credentials could still alter the pipeline definition or replace the artifact source if they hold the required permissions. KMS encryption is a data-protection control, not an authorization control for the pipeline resource itself.
- ✗
Use SNS to send notifications when the pipeline is updated
Why it's wrong here
Sending an Amazon SNS notification when the pipeline is updated only alerts operators after a modification has already been accepted by the CodePipeline service. It provides no enforcement mechanism to stop unauthorized changes because SNS is a publish/subscribe messaging service, not an authorization service. Notification-based monitoring is useful for incident response but cannot serve as a preventive guardrail against pipeline tampering.
- ✓
Attach an IAM policy that uses a condition to allow only specific users or roles to modify the pipeline
Why this is correct
Attaching an IAM policy that uses a condition such as aws:PrincipalArn to the CodePipeline administrative actions (for example, UpdatePipeline and CreatePipeline) is the correct preventive control. This restricts the set of principals who can modify the pipeline definition no matter how the request is made, and it can be combined with resource-level permissions and least-privilege scoping. It directly addresses unauthorized pipeline modifications at the authorization layer.
- ✗
Enable AWS CloudTrail and create a CloudWatch Events rule to notify on pipeline changes
Why it's wrong here
Enabling CloudTrail to log pipeline API activity and creating a CloudWatch Events rule to notify on pipeline changes gives you a forensic record and an alert after the fact, but it does not deny or block the offending operation. CloudTrail records the action only after authorization and execution have already occurred, making it a purely detective control. It complements IAM-based protection but cannot replace it because it does not participate in the policy evaluation process.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.