Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

Exhibit

Refer to the exhibit.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "codebuild:StartBuild",
                "codebuild:BatchGetBuilds"
            ],
            "Resource": "arn:aws:codebuild:us-east-1:123456789012:project/my-project"
        },
        {
            "Effect": "Allow",
            "Action": [
                "logs:CreateLogGroup",
                "logs:CreateLogStream",
                "logs:PutLogEvents"
            ],
            "Resource": "*"
        }
    ]
}

A DevOps engineer is reviewing the IAM policy attached to a CodeBuild service role. The policy allows starting builds and viewing logs. However, when CodeBuild tries to download artifacts from an S3 bucket in the same account, it fails with an access denied error. What is the missing permission?

⚠ Common exam trap

Candidates often confuse s3:GetObject with s3:PutObject or assume KMS decryption is always required, but the direct cause is the lack of read access to the S3 object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s3:GetObject

The error occurs because CodeBuild needs to download artifacts from S3, which requires the s3:GetObject permission on the bucket or object. Without this permission, the service role cannot read the artifact files, even though it can start builds and view logs. The s3:GetObject action is the specific permission that grants read access to S3 objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    s3:GetObject

    Why this is correct

    To download an object from an S3 bucket, the calling principal must be granted the s3:GetObject action. Without this permission, S3 returns an AccessDenied error even if other S3 actions like ListBucket or PutObject are allowed, so adding s3:GetObject is the minimal and correct fix for a build process that retrieves artifacts.

  • ✗

    kms:Decrypt

    Why it's wrong here

    kms:Decrypt is only required when the S3 objects are encrypted with a customer-managed AWS KMS key (SSE-KMS), because S3 must decrypt the object before returning it to the caller. The scenario has no mention of KMS or SSE-KMS, and the error is an S3 access denial rather than a KMS InvalidCiphertext or AccessDenied error, so adding kms:Decrypt would not resolve the underlying S3 permission gap.

  • ✗

    s3:PutObject

    Why it's wrong here

    s3:PutObject is the action used to upload or write objects to a bucket, not to read or download them. The build pipeline is attempting to fetch artifacts from S3, which is a read operation, so granting PutObject would be irrelevant and would not eliminate the AccessDenied error that occurs during the download attempt.

  • ✗

    logs:DescribeLogGroups

    Why it's wrong here

    logs:DescribeLogGroups is an IAM permission for Amazon CloudWatch Logs, used to list and inspect log group metadata. It has no bearing on S3 object access, and the error being reported is an S3 AccessDenied, not a CloudWatch Logs authorization failure, so adding this action would have no effect on the S3 download permission problem.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.