Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A DevOps team is implementing a CI/CD pipeline using AWS CodePipeline. The pipeline has a Source stage using CodeCommit, a Build stage using CodeBuild, and a Deploy stage using CloudFormation. The team wants to add manual approval before the Deploy stage for production deployments. How should this be configured?

⚠ Common exam trap

Test-takers frequently confuse automated notifications (like CloudWatch events or Lambda triggers) with the manual approval action, failing to recognize that CodePipeline's built-in Approval stage is the only native way to pause the pipeline for human intervention before deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an Approval stage to the pipeline with SNS topic for notification.

AWS CodePipeline natively supports Approval stages that can be configured to pause the pipeline and send a notification via an SNS topic. The SNS topic can be subscribed to by email, SMS, or other endpoints, allowing a manual approver to review the build output and then approve or reject the transition to the Deploy stage. This directly meets the requirement for a manual approval gate before production deployment without custom code or separate pipelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a CloudWatch event to send an email on build success.

    Why it's wrong here

    Configuring a CloudWatch Event (EventBridge) to send an email on build success is purely a notification mechanism; it does not introduce a blocking gate into the pipeline. The pipeline execution continues automatically past the build stage without human intervention, so this approach cannot satisfy a requirement for manual approval before production deployment. To pause and seek authorization, you must use a CodePipeline manual approval action, not an email trigger.

  • ✗

    Use a Lambda function to approve based on build status.

    Why it's wrong here

    A Lambda function cannot pause or approve a CodePipeline stage because approval is a dedicated action type that requires a human to call PutApprovalResult with the approval token; Lambda has no native 'approve' API for pipeline stages. While Lambda could theoretically be invoked by an event to call PutApprovalResult programmatically, that would bypass human oversight and is not a supported pattern for mandating a manual gate. The build status is already an automatic pipeline input, so using Lambda to evaluate it does not create the required human authorization checkpoint.

  • ✓

    Add an Approval stage to the pipeline with SNS topic for notification.

    Why this is correct

    Adding an Approval stage to the CodePipeline with an SNS topic is the correct approach because the approval action pauses all subsequent stage transitions until a designated reviewer clicks Approve (or Reject) in the console or invokes PutApprovalResult. The SNS topic sends email or other notifications to the approver, and the pipeline resumes only after the approval token is returned. This provides a auditable, controlled human decision point that is natively supported by CodePipeline.

  • ✗

    Create a separate pipeline for production and trigger it manually.

    Why it's wrong here

    Creating a separate pipeline for production and triggering it manually does not constitute an automated approval mechanism, as manual triggering simply starts the pipeline execution without an intervening authorization step tied to the upstream build. It also bypasses the unified CodePipeline orchestration, losing the pipeline-level execution history and the explicit approval token that the Approval action provides. A separate manual run still requires someone to remember to execute it, and it does not enforce a structured review or notification workflow.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A DevOps engineer is managing a CI/CD pipeline using AWS CodePipeline with multiple stages: Source (CodeCommit), Build (CodeBuild), Test (CodeBuild), and Deploy (CodeDeploy). The engineer wants to add manual approval steps before the Test and Deploy stages. Additionally, the pipeline should automatically roll back the deployment if the Deploy stage fails. Which two actions should the engineer take to implement these requirements? (Choose two.)

hard
  • A.Add an Approval action in the Test stage before the Test build action.
  • ✓ B.Insert a new stage between Build and Test, and add an Approval action to that stage.
  • ✓ C.In the CodeDeploy deployment group configuration, enable automatic rollback for deployment failure.
  • D.Add a Lambda function in the pipeline that triggers a rollback if the Deploy stage fails.
  • E.Configure the pipeline's Deploy stage to have a 'Rollback' action that runs on failure.

Why B: Manual approval actions in AWS CodePipeline must be added as a separate stage, not within an existing stage. By inserting a new stage between Build and Test and adding an Approval action, the pipeline pauses before the Test stage, allowing manual review. Option C is correct because CodeDeploy deployment groups support automatic rollback on deployment failure, which can be enabled in the deployment group configuration to revert to the last known good revision.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.