DOP-C02 SDLC Automation Practice Question
A DevOps engineer is setting up a CI/CD pipeline using AWS CodePipeline and AWS CodeBuild. The build environment requires specific software packages that are not available in the default CodeBuild environment. What is the MOST efficient way to customize the build environment?
⚠ Common exam trap
Candidates often confuse environment variables with actual software installation, thinking that setting variables in the buildspec file can bring in packages, when in fact environment variables only affect runtime behavior, not the software available in the build environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom Docker image with the required software and push it to Amazon ECR.
Creating a custom Docker image with the required software and pushing it to Amazon ECR allows you to pre-configure the build environment with all necessary packages. This approach avoids the overhead of installing packages during each build, reduces build time, and ensures consistency across builds. AWS CodeBuild supports custom images from Amazon ECR, making this the most efficient method for customizing the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a separate pipeline to pre-build the environment.
Why it's wrong here
Introducing a separate CodePipeline to pre-build the environment adds an extra layer of orchestration, requiring cross-pipeline dependency management (such as passing artifacts or version references) and increasing operational overhead. The main pipeline still needs to consume whatever the pre-build pipeline produces, and you now have two pipelines to sequence and monitor, which is overly complex for what should be a simple builder image setup. This approach does not inherently reduce build-time package installation or improve consistency compared to a single, purpose-built custom image.
- ✗
Add install commands in the buildspec file to install the packages during each build.
Why it's wrong here
Adding install commands to the buildspec's install phase makes every build dependent on external package repositories and network availability. This increases build duration because packages are downloaded and installed from scratch on each build, and it introduces non-determinism: if a package source is temporarily down or a version is yanked, the build fails unpredictably. It also means the build environment is mutated at runtime, yielding a cold, inconsistent environment instead of a stable, pre-provisioned toolchain.
- ✗
Modify the buildspec file to set environment variables that include the software packages.
Why it's wrong here
Setting environment variables in the buildspec only supplies configuration data to the build process; it does not execute package installers or place binaries on the filesystem. The required software must already exist in the container image or be installed by an earlier lifecycle phase (such as install), so merely referencing package names or paths in environment variables will not make them available. As a result, the build will fail when a command tries to invoke a missing tool, because the variable has not created the executable.
- ✓
Create a custom Docker image with the required software and push it to Amazon ECR.
Why this is correct
Creating a custom Docker image that includes all required software and pushing it to Amazon ECR lets you reference that image in the CodeBuild project's environment, so CodeBuild launches build containers from a pre-baked image. This avoids repeated package installation on every run, significantly reducing build time and removing dependence on internet-accessible package repositories during the build. The image provides a deterministic and immutable toolchain, which improves reproducibility, and you can version the image (using tags or image digests) and update it via its own build pipeline for rolling upgrades.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.