DOP-C02 SDLC Automation Practice Question
An organization uses AWS CodePipeline to deploy a static website to Amazon S3. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild that minifies assets), and a deploy stage (S3 deployment). The team wants to add a stage for running security vulnerability scans on the code. Which TWO options are viable?
⚠ Common exam trap
Test-takers frequently confuse Amazon Inspector (which scans runtime environments) with a source code scanner, or assume that Shield Advanced provides vulnerability scanning, when in fact it only mitigates DDoS attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a custom action in the pipeline that invokes a third-party scanning service via AWS Lambda.
AWS CodePipeline supports custom actions that can invoke external services via AWS Lambda. By creating a custom action, the team can integrate a third-party security scanning service directly into the pipeline, allowing the scan to run as a distinct stage between build and deploy. This approach ensures that the pipeline fails if vulnerabilities are detected, preventing insecure code from reaching the S3 bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a custom action in the pipeline that invokes a third-party scanning service via AWS Lambda.
Why this is correct
CodePipeline’s custom-action framework lets you define a stage gate backed by a Lambda function that calls your third-party scanner; the Lambda uses the job worker API (e.g., PutJobSuccessResult/PutJobFailureResult) to report the scan outcome, failing the stage if vulnerabilities are found. This approach is ideal when the scanning vendor doesn't have a built-in action provider and you need the scan to happen at a specific point in the pipeline before deployment.
- ✗
Enable AWS Shield Advanced to scan for vulnerabilities.
Why it's wrong here
AWS Shield Advanced is a managed DDoS protection service that defends against volumetric network and transport-layer attacks; it inspects nothing about your application code or build artifacts. Enabling it adds no vulnerability-scanning capability and would not introduce any scanning step into the pipeline, regardless of the resource type.
- ✗
Use Amazon Inspector to scan the source code.
Why it's wrong here
Amazon Inspector evaluates compute workloads—EC2 instances and container images in ECR—for software vulnerabilities, network reachability, and OS-level exposure; it is not a static application security testing (SAST) tool and does not parse HTML, JavaScript, or object source code. Because a static website artifact has no running OS or container image, Inspector cannot scan its source code or dependencies in the pipeline's pre-deploy phase.
- ✗
Add an S3 event notification to trigger a Lambda function that scans the S3 bucket.
Why it's wrong here
An S3 event notification attached to the deployment bucket triggers Lambda only after the sync step has already written the website objects, so scanning happens post-deployment with no ability to stop the release or trigger rollback. This violates the CI/CD principle of fail-fast: the vulnerable content is already public, and the pipeline has already reported success. It should instead run before the S3 deployment, e.g., as a custom action or within the build stage.
- ✓
Modify the buildspec in the build stage to include commands that run security scanning tools.
Why this is correct
The buildspec.yml file in the CodeBuild stage executes an ordered shell script with any CLI tools you choose; adding a scanner command like `npm audit` or `snyk test` and ensuring it returns a non-zero exit code on failure causes the build action to fail, preventing the artifact from being created. Because the build stage runs before the deploy action, this is a lightweight, fully supported way to embed a security gate without adding a third-party action provider. You must install the scanning binary in the build image or as a build phase dependency.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.