DOP-C02 SDLC Automation Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"codebuild:StartBuild",
"codebuild:BatchGetBuilds"
],
"Resource": "arn:aws:codebuild:us-east-1:123456789012:project/my-project"
},
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": "*"
}
]
}A DevOps engineer is reviewing the IAM policy attached to a CodeBuild service role. The policy allows starting builds and viewing logs. However, when CodeBuild tries to download artifacts from an S3 bucket in the same account, it fails with an access denied error. What is the missing permission?
⚠ Common exam trap
Candidates often confuse s3:GetObject with s3:PutObject or assume KMS decryption is always required, but the direct cause is the lack of read access to the S3 object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3:GetObject
The error occurs because CodeBuild needs to download artifacts from S3, which requires the s3:GetObject permission on the bucket or object. Without this permission, the service role cannot read the artifact files, even though it can start builds and view logs. The s3:GetObject action is the specific permission that grants read access to S3 objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
s3:GetObject
Why this is correct
To download an object from an S3 bucket, the calling principal must be granted the s3:GetObject action. Without this permission, S3 returns an AccessDenied error even if other S3 actions like ListBucket or PutObject are allowed, so adding s3:GetObject is the minimal and correct fix for a build process that retrieves artifacts.
- ✗
kms:Decrypt
Why it's wrong here
kms:Decrypt is only required when the S3 objects are encrypted with a customer-managed AWS KMS key (SSE-KMS), because S3 must decrypt the object before returning it to the caller. The scenario has no mention of KMS or SSE-KMS, and the error is an S3 access denial rather than a KMS InvalidCiphertext or AccessDenied error, so adding kms:Decrypt would not resolve the underlying S3 permission gap.
- ✗
s3:PutObject
Why it's wrong here
s3:PutObject is the action used to upload or write objects to a bucket, not to read or download them. The build pipeline is attempting to fetch artifacts from S3, which is a read operation, so granting PutObject would be irrelevant and would not eliminate the AccessDenied error that occurs during the download attempt.
- ✗
logs:DescribeLogGroups
Why it's wrong here
logs:DescribeLogGroups is an IAM permission for Amazon CloudWatch Logs, used to list and inspect log group metadata. It has no bearing on S3 object access, and the error being reported is an S3 AccessDenied, not a CloudWatch Logs authorization failure, so adding this action would have no effect on the S3 download permission problem.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.