DOP-C02 SDLC Automation Practice Question
A DevOps team is implementing a CI/CD pipeline for a microservices architecture. Each microservice is built and deployed independently. The team wants to ensure that only one build runs per microservice at a time to avoid resource contention, and that the build artifacts are stored securely. Which THREE steps should the team take?
⚠ Common exam trap
It's easy for candidates to confuse AWS CodeArtifact (for package management) with S3 (for artifact storage), or they assume that creating separate pipelines inherently enforces concurrency limits, when in fact concurrency must be explicitly configured in the CodeBuild project settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable versioning on the S3 bucket storing build artifacts
Option B is correct because enabling versioning on the S3 bucket preserves every revision of the build artifacts, allowing recovery of previous versions and protecting against accidental overwrites or deletions, which supports secure artifact storage. Option C is correct because configuring a concurrency limit in each microservice's CodeBuild project ensures only one build for that microservice runs at a time, directly preventing resource contention as required. Option E is correct because enabling server-side encryption on the S3 bucket encrypts artifacts at rest using AWS-managed or KMS keys, satisfying the requirement to store build artifacts securely. Option A is not correct because AWS CodeArtifact is a package/dependency repository for artifacts like npm, Maven, and PyPI packages, not the general build-artifact store used by CodePipeline, and the scenario's secure storage requirement is met by S3 with versioning and encryption. Option D is not correct because creating a separate CodePipeline per microservice supports independent deployment but does not by itself enforce one build at a time or secure artifact storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store build artifacts in AWS CodeArtifact
Why it's wrong here
AWS CodeArtifact is a package repository service designed to store and retrieve software dependencies such as Maven, npm, PyPI, and NuGet packages. Build artifacts produced by CodeBuild (e.g., compiled JARs, ZIPs, or deployment bundles) are not typical CodeArtifact payloads, and CodeArtifact does not serve as the pipeline artifact store. Even if you attempted to store build outputs there, this does nothing to retain multiple versions for rollback or to manage execution concurrency.
- ✓
Enable versioning on the S3 bucket storing build artifacts
Why this is correct
Enabling S3 bucket versioning on the bucket that stores CodePipeline build artifacts preserves every object version, including each build output. When a deployment needs to roll back, you can retrieve a previous artifact version directly from S3 or point the pipeline stage to that exact version. Versioning is a prerequisite for using S3 as CodePipeline's default artifact store in a way that supports safe, reproducible rollbacks without losing prior builds.
- ✓
Configure a concurrency limit in the CodeBuild project for each microservice
Why this is correct
Configuring a concurrency limit in the CodeBuild project for each microservice caps the number of simultaneous builds that CodeBuild can run for that specific project. By setting the limit to 1, you force builds for a given microservice to execute serially, preventing multiple pipeline executions from producing conflicting artifacts or deploying out of order. This directly addresses the problem of concurrent builds on the same codebase, which is separate from artifact retention or encryption.
- ✗
Create a separate CodePipeline for each microservice
Why it's wrong here
Creating a separate CodePipeline per microservice does not constrain how many builds or deployments can run concurrently for the same microservice. If a developer pushes multiple commits rapidly, a single pipeline can still execute multiple runs in parallel, and multiple pipelines for the same service would worsen the concurrency issue. Concurrency must be enforced at the CodeBuild project level (or via pipeline execution limits), not by merely separating pipeline definitions.
- ✓
Enable server-side encryption on the S3 bucket storing build artifacts
Why this is correct
Enabling server-side encryption on the S3 artifact bucket (SSE-S3 or SSE-KMS) protects build artifacts at rest, ensuring that unauthorized users cannot read the stored outputs. However, encryption does not retain old versions of an artifact, nor does it provide any capability to roll back to a previous build. It is a security best practice, but it is unrelated to the stated requirement of being able to revert to an older artifact after a failed deployment.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.