DOP-C02 SDLC Automation Practice Question
A DevOps team is using AWS CodeBuild to run integration tests against a test database. The database is an Amazon RDS instance in a private subnet. The CodeBuild project is configured to run in a VPC. Which THREE steps are required to allow CodeBuild to access the RDS instance?
⚠ Common exam trap
Many candidates confuse the need for a NAT gateway (which is for internet access) with the requirement for internal VPC routing, or they mistakenly think that placing RDS in a public subnet is necessary for CodeBuild to reach it, when in fact private subnet communication via security groups and route tables is the correct approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the security group attached to the RDS instance allows inbound traffic from the CodeBuild security group.
The security group attached to the RDS instance must explicitly allow inbound traffic from the security group associated with the CodeBuild project's elastic network interfaces. This is a fundamental network access control in AWS: security groups act as virtual firewalls, and without an inbound rule permitting traffic from the CodeBuild security group on the database port (e.g., 3306 for MySQL), the connection will be blocked regardless of other network configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the RDS instance in a public subnet with a public IP.
Why it's wrong here
Placing the RDS instance in a public subnet and assigning it a public IP directly exposes the database to the internet, which violates security best practices and is unnecessary for CodeBuild connectivity. Even with a public IP, CodeBuild would still need a routable path and would typically require a NAT gateway or internet gateway for outbound traffic, but this approach introduces a severe attack surface without resolving the core networking issue. RDS instances should reside in private subnets, with access controlled through security groups and VPC routing.
- ✓
Ensure the security group attached to the RDS instance allows inbound traffic from the CodeBuild security group.
Why this is correct
Security groups act as a virtual firewall at the instance level. By referencing the CodeBuild project's security group as a source in the RDS security group's inbound rule, you allow traffic specifically from the Elastic Network Interfaces (ENIs) that CodeBuild uses when it runs inside the VPC. This is the most direct and least-privileged way to permit the integration tests to reach RDS, because it avoids opening the database to CIDR ranges or the entire VPC. It also updates automatically if CodeBuild's IP addresses change, as long as the security group ID remains the same.
- ✗
Attach a NAT gateway to the VPC so that CodeBuild can route to RDS.
Why it's wrong here
A NAT gateway enables outbound internet connectivity from private subnets, allowing resources like CodeBuild to reach public endpoints (e.g., package registries or external APIs). It does not establish or improve routing between two private resources within the same VPC; RDS and CodeBuild communicate using VPC-internal routes and security groups. Adding a NAT gateway would neither help CodeBuild reach RDS nor mitigate any security group misconfiguration, so it is an unnecessary and costly addition.
- ✓
Ensure the VPC's route tables have routes to allow traffic between CodeBuild subnets and RDS subnets.
Why this is correct
VPC route tables determine how traffic is forwarded between subnets and network boundaries. For CodeBuild (running in one or more subnets) to reach RDS (in possibly different subnets) within the same VPC, the route tables must contain entries that cover the destination RDS subnets' CIDR ranges; typically the local VPC route already provides this if both subnets are in the same VPC. If the local route is missing or the subnets are in different VPCs, explicit routes would be needed, but with a standard single-VPC setup this is usually already satisfied. This option is correct as a prerequisite, but it is not the sole control: the security group inbound rule is still required to authorize the traffic, making the security group configuration the definitive fix.
- ✓
Configure the CodeBuild project to use a VPC that has access to the RDS instance.
Why this is correct
For CodeBuild to access private resources like an RDS instance, the build project must be configured to run in a VPC. CodeBuild then creates ENIs in the specified subnets and uses those subnets' route tables and the VPC's security groups for network access. Without VPC configuration, CodeBuild runs in AWS-managed infrastructure outside your VPC and cannot reach a private RDS endpoint, even with network ACLs or security groups permitting traffic. This is a foundational step—you must associate the CodeBuild project with the VPC that contains the RDS instance before any security group or route table rules can take effect.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.