Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CodeBuild to run security scans on code before deployment. They want to ensure that if the security scan fails, the build is marked as FAILED and no further pipeline stages execute. What should they add to the buildspec?

⚠ Common exam trap

Test-takers frequently confuse the 'reports' section (which only generates test reports) with the mechanism that actually fails the build, forgetting that only the exit code of commands in the 'phases' section determines build success or failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'phases' section with a command that exits with a non-zero status on failure.

In AWS CodeBuild, the build process is controlled by the 'phases' section of the buildspec file. Each phase runs a series of commands sequentially, and if any command exits with a non-zero status (e.g., a security scan tool returns a failure exit code), CodeBuild immediately marks the build as FAILED and stops further execution. This ensures that no subsequent pipeline stages are triggered, as the build status propagates to the pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the 'artifacts' section to define failure conditions.

    Why it's wrong here

    The 'artifacts' section in AWS CodeBuild defines which files or directories are uploaded to an output location (e.g., S3) after the build completes. It does not influence build lifecycle events or evaluation of command exit codes. A build's success or failure is determined solely by the exit status of commands executed in the 'phases' sections, not by artifact configuration. Therefore, placing failure conditions here would have no effect on the build result.

  • ✗

    Use the 'env' section to set a variable that fails the build.

    Why it's wrong here

    The 'env' section imports environment variables, secrets from AWS Secrets Manager or Parameter Store, and can set build-time variables for use in your commands. Environment variables are passed to the build process but AWS CodeBuild does not monitor or react to their values when deciding build pass/fail. The build's status is derived from exit codes of the command in each phase, not from variable assignments. Merely assigning a variable, even one that 'looks like' a failure flag, never causes the build to fail.

  • ✗

    Use the 'reports' section to mark the build as failed if tests fail.

    Why it's wrong here

    The 'reports' section configures test report groups (e.g., JUnit XML output) that CodeBuild collects and displays in the console. While reports can show test failures, they are purely observational and do not alter the build status. A build with failing tests in reports still succeeds unless a phase command exits non-zero. Thus, this section cannot be used to make the build fail; it only records and categorizes results for later analysis.

  • ✓

    Use the 'phases' section with a command that exits with a non-zero status on failure.

    Why this is correct

    The 'phases' section is the correct place to implement failure logic because CodeBuild evaluates the exit status of each shell command run in its sub-sections (install, pre_build, build, post_build). If any command exits with a non-zero status, the build is stopped immediately and marked as FAILED. For a security scan, you would invoke your scanning tool in the 'build' phase and rely on that exit status to signal failure. This is the only mechanism that directly controls the build outcome.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.