Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer manages a build account where CodeBuild projects run in a VPC to reach an internal artifact repository. The projects must pull a database password from AWS Secrets Manager at build time. The build role's IAM policy already grants secretsmanager:GetSecretValue on the secret ARN, but every build fails with a connection timeout when the AWS CLI attempts the call. The VPC has private subnets, a NAT gateway, and a VPC endpoint for Amazon S3 only. What is the MOST operationally efficient change that lets the builds retrieve the secret while keeping the traffic off the public internet?

⚠ Common exam trap

The trap here is assuming that the existing Amazon S3 gateway endpoint, or any gateway endpoint type, can be extended to Secrets Manager, when only interface endpoints support that service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an interface VPC endpoint for secretsmanager in the build VPC, and attach a security group that allows HTTPS from the build subnet CIDR.

Interface VPC endpoints use AWS PrivateLink to create private ENIs in the subnet, letting CodeBuild reach Secrets Manager without NAT or internet egress. Because the endpoint is an ENI, its security group must allow inbound HTTPS from the build subnets, and the private DNS name for secretsmanager is resolved locally. Gateway endpoints only serve S3 and DynamoDB, so the existing S3 endpoint cannot cover this call.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the build role's trust policy to allow secretsmanager.amazonaws.com to assume it, so the CLI call is authorized inside the VPC.

    Why it's wrong here

    Trust policies govern which principals may assume a role and have no bearing on network reachability. The failure is a connection timeout, meaning packets never reach the Secrets Manager endpoint, so no IAM adjustment can resolve it. The build role already holds the required GetSecretValue permission, which further shows authorization is not the problem here.

  • ✓

    Create an interface VPC endpoint for secretsmanager in the build VPC, and attach a security group that allows HTTPS from the build subnet CIDR.

    Why this is correct

    This is correct because an interface endpoint (powered by AWS PrivateLink) places an elastic network interface for secretsmanager inside the subnet, so the CodeBuild container reaches the service privately without NAT or internet egress. The endpoint's security group must permit TCP 443 inbound from the build instances, which the scenario's S3 gateway endpoint cannot provide for Secrets Manager.

  • ✗

    Enable public access on the secret and add an internet gateway route to the private subnet route tables so the CLI can reach the regional endpoint.

    Why it's wrong here

    Adding an internet gateway route to a subnet makes it public and exposes build traffic to the internet, which contradicts the requirement to keep traffic private. Secrets Manager does not have a per-secret public access toggle, so the first half of this change is not even a real setting. This approach also bypasses the existing NAT design unnecessarily.

  • ✗

    Add a gateway VPC endpoint for secretsmanager to the route tables of the private subnets so the CLI calls resolve to the endpoint.

    Why it's wrong here

    Gateway endpoints exist only for Amazon S3 and DynamoDB, so no gateway endpoint type is offered for Secrets Manager. Attempting to create one is impossible, and even a route-table entry would not give the CodeBuild container a private DNS name or network interface for the service. This option misapplies a service that does not support the gateway endpoint model.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.