Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A team uses AWS CodePipeline to orchestrate deployments. They want to integrate a manual approval step before deploying to production. Which action should they take?

⚠ Common exam trap

Candidates often confuse the manual approval action's dependency on SNS with the idea that simply adding an SNS topic to the pipeline creates an approval step, when in fact the approval action must be explicitly added as a stage action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a manual approval action to the pipeline before the production deployment stage.

AWS CodePipeline natively supports a manual approval action that can be added as a stage before the production deployment. This action pauses the pipeline and sends a notification (via Amazon SNS) to specified approvers, who can then approve or reject the deployment through the AWS Management Console, CLI, or API. No custom code or external services are required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Lambda function to send an approval request email and wait for HTTP response.

    Why it's wrong here

    AWS Lambda actions in CodePipeline run a function and return an invocation result, but they are not designed to suspend a stage pending human interaction. CodePipeline treats a successful Lambda invocation as success and advances the execution; there is no built-in capability for a Lambda function to 'wait' for an HTTP response as an approval gate unless you build a custom orchestrator that stops and restarts executions, which is fragile and unsupported. A Lambda can send email, but it cannot pause the pipeline for an indefinitely long human review, making this approach incorrect.

  • ✓

    Add a manual approval action to the pipeline before the production deployment stage.

    Why this is correct

    Adding a manual approval action is the native and correct way to gate a production deployment in CodePipeline. The action is an Approval type stage step that pauses the pipeline execution until an authorized IAM principal explicitly clicks Approve or Reject in the console, or calls the appropriate AWS SDK/CLI commands. This provides a built-in, auditable human checkpoint with no additional infrastructure, and it can optionally send SNS or EventBridge notifications to reviewers.

  • ✗

    Add an Amazon CloudWatch Events rule to pause the pipeline before the production stage.

    Why it's wrong here

    Amazon CloudWatch Events (now Amazon EventBridge) can detect pipeline state changes and trigger targets, but it cannot mutate or pause a pipeline's execution flow. A rule can fire on events like 'execution started' or 'approval needed' and invoke a Lambda or notify SNS, but it cannot insert a hold point before a stage. To actually stop execution before production, you would need the pipeline to contain an Approval action or use the stage transition disable feature; a CloudWatch Events rule is not a mechanism for pausing.

  • ✗

    Add an Amazon SNS topic to the pipeline and require subscription confirmation.

    Why it's wrong here

    Using Amazon SNS as an 'action' in CodePipeline is impossible because SNS topics are messaging endpoints, not pipeline action categories. Even if you assign an SNS topic as a notification target for the pipeline, subscribing and confirming a topic has no effect on execution state—it only delivers messages. CodePipeline has no action that 'requires subscription confirmation,' and the pipeline would not pause or wait for a subscriber; only an Approval action can provide that gate.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.