Courseiva
SDLC Automation →easyMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CodeBuild to build Docker images and push them to Amazon ECR. The buildspec.yml includes a post_build step that runs a security scan. The team wants to ensure that only images that pass the security scan are tagged as 'latest'. Which approach should be used?

⚠ Common exam trap

Test-takers frequently think deleting a tag after a failure is sufficient, but they overlook the race condition where the 'latest' tag is already published and could be consumed before deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the post_build phase, run the security scan, and if it passes, tag the image with 'latest' and push.

It ensures that only images passing the security scan receive the 'latest' tag. By running the scan in the post_build phase and conditionally tagging only on success, the team avoids ever pushing a vulnerable image with the 'latest' tag. This approach follows the principle of atomic tagging, where the tag is applied only after all validation steps pass.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Build the image with the 'latest' tag first, then run the security scan. If it fails, delete the 'latest' tag.

    Why it's wrong here

    This approach prematurely tags a potentially vulnerable image as 'latest' before any security validation has completed. Once that tag is pushed to Amazon ECR, any downstream consumer (ECS, EKS, or other services) that pulls 'latest' will receive the vulnerable image, and even if the tag is later deleted, the underlying image digest may already have been pulled and deployed. Deleting a tag in ECR does not automatically delete the underlying image, leaving a stale artifact; this creates an unnecessary exposure window and does not prevent accidental use before cleanup.

  • ✓

    In the post_build phase, run the security scan, and if it passes, tag the image with 'latest' and push.

    Why this is correct

    This is the correct approach because it guarantees the 'latest' tag is only ever applied to an image that has successfully passed the defined security gate. In the post_build phase of CodeBuild, you can run a local container scanner (e.g., Trivy, Snyk, or Anchore) and only when the exit code indicates a pass do you execute `docker tag` to relabel the built image as `latest` followed by `docker push`. This ensures the 'latest' tag remains immutable and clean, with no vulnerable image ever being exposed under that tag during the build or scan window.

  • ✗

    Use ECR lifecycle policies to remove images that do not pass the security scan.

    Why it's wrong here

    Amazon ECR lifecycle policies are rules that operate solely on image age and tag count (e.g., expire untagged images older than X days or keep only N images), and they cannot evaluate scan findings such as CVSS severity scores. Lifecycle actions are executed automatically by ECR without awareness of the results from basic or enhanced scanning, so they cannot selectively remove images that failed a security scan. To act on scan results you must build an event-driven workflow (e.g., Amazon EventBridge and a Lambda function) that calls the ECR API to delete or quarantine failing image digests.

  • ✗

    Tag the image with 'latest' only after the build phase, regardless of scan results.

    Why it's wrong here

    Tagging the image with 'latest' immediately after the build phase, without any reference to the security scan outcome, completely bypasses the requirement that only passing images receive the 'latest' tag. In CodeBuild, the build phase completes before the post_build phase, so this action promotes the image before a scan is even initiated, and there is no conditional logic to stop it. This leaves a vulnerable window like the first option but without any fallback cleanup mechanism, making it strictly non-compliant and a dangerous practice.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.