Courseiva
SDLC Automation →easyMultiple Select

DOP-C02 SDLC Automation Practice Question

A DevOps team is implementing a CI/CD pipeline for a microservices application deployed on Amazon ECS. They want to automatically build, test, and deploy container images to Amazon ECR and then update the ECS service. Which TWO steps are essential to achieve this goal?

⚠ Common exam trap

Many exam-takers confuse AWS CodeDeploy with AWS CodePipeline or AWS CloudFormation for updating ECS services, but CodeDeploy is the specific service designed for controlled ECS deployments with traffic shifting and rollback capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CodeDeploy to update the ECS service with a new task definition.

AWS CodeDeploy is the native AWS service for managing ECS rolling or blue/green deployments. It orchestrates the creation of a new ECS task definition, registers it, and updates the ECS service to use the new task definition, ensuring zero-downtime deployments. Option C is correct because AWS CodeBuild can execute build commands from a buildspec.yml file to build a Docker image and push it to Amazon ECR using the built-in AWS CLI or Docker commands, which is a fundamental step in a CI/CD pipeline for containerized applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS CodeDeploy to update the ECS service with a new task definition.

    Why this is correct

    AWS CodeDeploy provides a native ECS deployment mechanism that can shift traffic from the old to the new task definition using blue/green or rolling configurations with an Application Load Balancer. In a CodePipeline-based CI/CD flow, this is the deployment action that makes the newly built image actually run on the ECS service, so it is essential to the pipeline.

  • ✗

    Use AWS Secrets Manager to store Docker credentials.

    Why it's wrong here

    Amazon ECR authentication does not require Docker credentials stored in Secrets Manager; instead, CodeBuild and ECS derive authorization from AWS IAM, using aws ecr get-login-password to generate a temporary docker login token. Storing Docker Hub credentials in Secrets Manager would be irrelevant here because the image is being pushed to and pulled from ECR, which authenticates via IAM roles and the GetAuthorizationToken API. Therefore this is not a needed pipeline step.

  • ✓

    Use AWS CodeBuild to build the Docker image and push it to Amazon ECR.

    Why this is correct

    AWS CodeBuild can run in a Docker-capable environment and is the correct service to compile the microservice, build a Docker image from a Dockerfile, and push that image to Amazon ECR using aws ecr get-login-password before docker push. It integrates directly with CodePipeline artifacts, and the resulting ECR image URI becomes the input for the subsequent ECS deployment. This is the build stage of the CI/CD pipeline.

  • ✗

    Use AWS X-Ray for tracing.

    Why it's wrong here

    AWS X-Ray is a distributed tracing service that provides end-to-end visibility into requests as they flow through microservices at runtime, which is useful for debugging latency and errors in production. It does not participate in building, testing, or deploying code, so it is not an essential element of a CI/CD pipeline. Adding X-Ray would be a separate observability feature after the service is deployed.

  • ✗

    Use Amazon CodeGuru for code review.

    Why it's wrong here

    Amazon CodeGuru Reviewer uses machine learning to analyze source code and detect defects and security issues, but it is an optional quality-gate tool rather than a required CI/CD component. The pipeline described here needs build and deploy stages for a microservice to ECS, and CodeGuru does not build, package, or deploy anything. Its absence does not prevent the pipeline from functioning, making it non-essential.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.