DOP-C02 Security and Compliance Practice Question
A DevOps engineer is troubleshooting a failed CodeBuild project. The build fails with an error: 'Access Denied: Unable to put object to S3.' The build project has an S3 bucket as the artifact store. What should the engineer do to resolve this issue?
⚠ Common exam trap
DOP-C02 often tests the distinction between source bucket permissions (GetObject) and artifact bucket permissions (PutObject) — candidates confuse the two and apply the wrong S3 action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add s3:PutObject permission to the CodeBuild service role for the artifact bucket.
The error 'Access Denied: Unable to put object to S3' indicates the CodeBuild service role lacks s3:PutObject permission on the artifact bucket. CodeBuild assumes this role to upload build artifacts, so the fix is to attach an IAM policy granting s3:PutObject (and typically s3:GetBucketLocation, s3:ListBucket) for the artifact bucket to the CodeBuild service role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add s3:PutObject permission to the CodeBuild service role for the artifact bucket.
Why this is correct
The CodeBuild service role is an IAM role that grants the build project permission to call AWS APIs. When CodeBuild uploads build artifacts to an S3 bucket, it must have the s3:PutObject action allowed on that artifact bucket. The failure occurs at the upload step because the role currently lacks write access; adding s3:PutObject to the role's policy for the artifact bucket's ARN resolves the AccessDenied error.
- ✗
Enable server-side encryption on the artifact bucket.
Why it's wrong here
Enabling server-side encryption on the artifact bucket controls how objects are encrypted at rest within S3, but it does not grant IAM permissions to the CodeBuild service role. The build is failing because the role lacks the s3:PutObject action, an authorization issue, not a data-protection or encryption configuration issue. Even if encryption were enabled, the upload would still be denied because the role still cannot perform the PutObject API call.
- ✗
Enable CloudWatch Logs for the build project.
Why it's wrong here
CloudWatch Logs integration for a CodeBuild project records build logs and metrics, including console output and execution status, but it does not affect S3 artifact uploads. The artifact upload failure is caused by missing IAM permissions on the service role, not by missing observability features. Enabling CloudWatch Logs would provide better debugging visibility but would not change the role's ability to call s3:PutObject.
- ✗
Add s3:GetObject permission to the CodeBuild service role for the source bucket.
Why it's wrong here
Adding s3:GetObject permission for the source bucket grants CodeBuild read access to the source code repositories stored in S3, which is necessary during the download phase of a build. However, the reported failure occurs during the artifact publishing phase, where CodeBuild writes the build output to the artifact bucket using s3:PutObject. The error is specific to an upload permission, so granting a read permission on a different bucket cannot resolve the problem.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.