Courseiva
SDLC Automation →easyMultiple Select

DOP-C02 SDLC Automation Practice Question

A DevOps engineer is setting up a CI/CD pipeline for a Python application using AWS CodePipeline. The pipeline includes a build stage with CodeBuild and a deploy stage that runs an AWS CLI command to update a Lambda function. Which THREE steps are necessary to ensure the pipeline can update the Lambda function? (Choose 3)

⚠ Common exam trap

The trap here is that candidates might think a CloudWatch Events trigger is needed to initiate the update, but the pipeline itself is the orchestrator; the real requirement is proper IAM permissions and command definition within the buildspec.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the AWS CLI command in the buildspec file or as a separate script in the source repository.

The AWS CLI command to update the Lambda function must be defined in the buildspec file or as a script in the source repository so that CodeBuild can execute it during the deploy stage. This ensures the pipeline has the exact command to run, and it becomes part of the version-controlled build specification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store the AWS CLI command in the buildspec file or as a separate script in the source repository.

    Why this is correct

    The AWS CLI command that updates the Lambda function must be defined in the buildspec file or in a script committed to the source repository. CodeBuild executes the buildspec during the build phase, so placing the command there ensures it is run as part of the pipeline after the artifact is produced. Keeping it in source control also makes the deployment step reproducible, auditable, and versioned alongside the application code.

  • ✓

    Grant the CodePipeline service role permission to pass the CodeBuild IAM role to CodeBuild.

    Why this is correct

    CodePipeline must be granted iam:PassRole permission on the CodeBuild execution role so that the pipeline can start a CodeBuild project with that role. Without this, CodePipeline may fail with a permissions error even if the CodeBuild role itself has all Lambda permissions. This is a distinct IAM delegation step—CodePipeline is not assuming the role directly, but passing it to CodeBuild for the build job.

  • ✗

    Configure a CloudWatch Events rule to trigger the pipeline when the Lambda function is updated.

    Why it's wrong here

    A CloudWatch Events rule can trigger a pipeline when certain events occur, but here we are not trying to trigger a pipeline in response to a Lambda update—we are trying to deploy the updated code to Lambda. This rule would create an unnecessary circular dependency (Lambda update → pipeline → Lambda update) and does not address the required deployment action. Pipeline triggers are irrelevant to the deploy step's execution.

  • ✓

    Create an IAM role for CodeBuild that includes permissions to invoke 'lambda:UpdateFunctionCode'.

    Why this is correct

    The IAM role that CodeBuild assumes must include the lambda:UpdateFunctionCode permission so that the AWS CLI command can successfully update the Lambda function's code. This is the fine-grained action required for the `aws lambda update-function-code` call, and it must be attached to the CodeBuild service role, not the CodePipeline role. Without this permission, the CLI command will fail with an AccessDenied error, even if all other permissions are correct.

  • ✗

    Use AWS CodeDeploy instead of the AWS CLI to update the Lambda function.

    Why it's wrong here

    CodeDeploy is designed for deploying Lambda applications with managed deployment strategies, traffic shifting, and rollbacks, but the question explicitly describes using the AWS CLI to update the function. CodeDeploy would be an alternative architecture, not a required or inherently better choice here, and introducing it adds complexity (Application, DeploymentGroup, AppSpec) that is not necessary. The question asks for the correct approach for a CLI-based update, so replacing the CLI with CodeDeploy would change the answer rather than satisfy it.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.