Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

Network Topology
$ aws codebuild batch-get-projectsnames my-projectRefer to the exhibit.```$ aws codebuild list-projects"projects": ["my-project""name": "my-project","source": {"type": "CODECOMMIT","location": "https://git-codecommit.us-east-1.amazonaws.com/v1/repos/my-repo"},"environment": {"type": "LINUX_CONTAINER","image": "aws/codebuild/standard:5.0","computeType": "BUILD_GENERAL1_SMALL","environmentVariables": []"serviceRole": "arn:aws:iam::123456789012:role/CodeBuildServiceRole","artifacts": {"type": "S3","location": "my-build-artifacts"

A DevOps engineer runs the above AWS CLI commands and notices that the CodeBuild project 'my-project' exists but builds fail with the error 'Access Denied' when trying to fetch source code from CodeCommit. The IAM role 'CodeBuildServiceRole' has a policy that allows 'codecommit:GitPull' on all repositories. What is the most likely cause of the failure?

⚠ Common exam trap

The trap here is that candidates often focus on the IAM policy permissions (e.g., 'codecommit:GitPull') and overlook the necessity of a trust policy, assuming that if the policy allows the action, the role is automatically usable by the service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role does not have a trust policy that allows CodeBuild to assume the role.

The error 'Access Denied' when CodeBuild tries to fetch source code from CodeCommit typically indicates that the IAM role CodeBuild is using does not have the necessary permissions to perform the action. Even though the role 'CodeBuildServiceRole' has a policy allowing 'codecommit:GitPull', the role itself must have a trust policy that allows the CodeBuild service to assume it. Without a proper trust policy, CodeBuild cannot assume the role, and any attached permissions are irrelevant, leading to an access denied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM role does not have permissions to access the CodeCommit repository.

    Why it's wrong here

    The IAM role actually contains a policy that grants 'codecommit:GitPull' on the repository, which is the only CodeCommit permission needed for CodeBuild to download source. If the role lacked repository access, the build would fail during the source fetch phase with an authorization error, not before the service could even assume the role. Therefore this is not the cause of the failure described.

  • ✓

    The IAM role does not have a trust policy that allows CodeBuild to assume the role.

    Why this is correct

    CodeBuild first calls sts:AssumeRole to obtain temporary credentials for the service role, and this requires the role's trust policy to include codebuild.amazonaws.com as a trusted service principal. The permissions policy may be correct, but if the trust policy is missing or misconfigured, CodeBuild is not authorized to assume the role and the build fails before any repository action occurs. This is the classic cause when CLI output verifies the repository and the permissions policy, yet the build cannot start.

  • ✗

    The CodeCommit repository does not exist.

    Why it's wrong here

    The AWS CLI command used to describe or get the repository returned output that includes the repository's clone URL and other metadata, which would only happen if the repository exists and the caller has access. If the repository did not exist, the CLI would raise a 'RepositoryDoesNotExistException' and there would be no repository location to show in the output. The presence of this location confirms the repository is valid.

  • ✗

    The source location in the build project is incorrect.

    Why it's wrong here

    The source location configured in the build project exactly matches the repository location returned by the AWS CLI output, so the build is pointing to the correct CodeCommit repository. An incorrect source location would cause a distinct failure, such as a 'SourceRequired' error or a network/URL resolution failure when CodeBuild tries to clone, not a general IAM role assumption error. Since the location is verified, this option is not the cause of the issue.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.