Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

A DevOps engineer manages a CodePipeline with a CodeCommit source, a CodeBuild test stage, and a manual approval before a production deploy stage. Audit requires that only the specific commit that passed testing can be deployed, and that no new commits pushed to the branch between test and approval can reach production. What should the engineer configure to guarantee this?

⚠ Common exam trap

The trap here is treating the source branch as the unit of control, when the deploy stage actually consumes the artifact of the pipeline execution, not the latest branch state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Keep the same pipeline execution through approval so the approved execution deploys the artifact produced earlier in that same execution.

The requirement is that the tested artifact, not just the branch, is what reaches production. Within one CodePipeline execution, artifacts are immutable across stages, so approving and continuing that execution deploys the tested revision. A later push starts a separate execution that cannot bypass test and approval, which preserves the audit guarantee without custom comparison logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the source action to use a specific commit ID as the source revision and disable polling so the pipeline only runs for that commit.

    Why it's wrong here

    Pinning a commit ID in the source action fixes the revision for a single execution, but the pipeline still triggers on new commits if event-based triggers remain. Disabling polling does not disable event triggers, so a new push can start a new execution and produce a different artifact that reaches production.

  • ✗

    Add a stage-level condition or gate that fails the pipeline if the source artifact revision differs from the revision recorded at test time.

    Why it's wrong here

    A custom check comparing revisions can detect drift, but it is a workaround that requires custom logic and still allows a pipeline execution for the new commit to proceed up to the gate. It does not inherently prevent a new commit's artifact from being promoted, and it adds maintenance overhead compared with native execution controls.

  • ✗

    Enable the pipeline's artifact bucket versioning and add a lifecycle rule that expires old artifact versions after 30 days.

    Why it's wrong here

    Versioning the artifact bucket preserves historical artifacts but does not change which artifact the deploy stage consumes. The deploy stage uses the artifact produced by the current pipeline execution, so versioning and lifecycle rules have no effect on preventing later commits from being deployed and only affect storage retention.

  • ✓

    Keep the same pipeline execution through approval so the approved execution deploys the artifact produced earlier in that same execution.

    Why this is correct

    A single pipeline execution carries its own artifacts from source through deploy. If the approval is part of that execution, the deploy stage consumes the exact artifact built and tested earlier, so commits pushed after the test stage start a new execution that must itself pass testing and approval, leaving the original execution's artifact intact.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.