Courseiva
SDLC Automation →mediumMultiple Select

DOP-C02 SDLC Automation Practice Question

An organization uses AWS CodePipeline to deploy a static website to Amazon S3. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild that minifies assets), and a deploy stage (S3 deployment). The team wants to add a stage for running security vulnerability scans on the code. Which TWO options are viable?

⚠ Common exam trap

Test-takers frequently confuse Amazon Inspector (which scans runtime environments) with a source code scanner, or assume that Shield Advanced provides vulnerability scanning, when in fact it only mitigates DDoS attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a custom action in the pipeline that invokes a third-party scanning service via AWS Lambda.

AWS CodePipeline supports custom actions that can invoke external services via AWS Lambda. By creating a custom action, the team can integrate a third-party security scanning service directly into the pipeline, allowing the scan to run as a distinct stage between build and deploy. This approach ensures that the pipeline fails if vulnerabilities are detected, preventing insecure code from reaching the S3 bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a custom action in the pipeline that invokes a third-party scanning service via AWS Lambda.

    Why this is correct

    CodePipeline’s custom-action framework lets you define a stage gate backed by a Lambda function that calls your third-party scanner; the Lambda uses the job worker API (e.g., PutJobSuccessResult/PutJobFailureResult) to report the scan outcome, failing the stage if vulnerabilities are found. This approach is ideal when the scanning vendor doesn't have a built-in action provider and you need the scan to happen at a specific point in the pipeline before deployment.

  • ✗

    Enable AWS Shield Advanced to scan for vulnerabilities.

    Why it's wrong here

    AWS Shield Advanced is a managed DDoS protection service that defends against volumetric network and transport-layer attacks; it inspects nothing about your application code or build artifacts. Enabling it adds no vulnerability-scanning capability and would not introduce any scanning step into the pipeline, regardless of the resource type.

  • ✗

    Use Amazon Inspector to scan the source code.

    Why it's wrong here

    Amazon Inspector evaluates compute workloads—EC2 instances and container images in ECR—for software vulnerabilities, network reachability, and OS-level exposure; it is not a static application security testing (SAST) tool and does not parse HTML, JavaScript, or object source code. Because a static website artifact has no running OS or container image, Inspector cannot scan its source code or dependencies in the pipeline's pre-deploy phase.

  • ✗

    Add an S3 event notification to trigger a Lambda function that scans the S3 bucket.

    Why it's wrong here

    An S3 event notification attached to the deployment bucket triggers Lambda only after the sync step has already written the website objects, so scanning happens post-deployment with no ability to stop the release or trigger rollback. This violates the CI/CD principle of fail-fast: the vulnerable content is already public, and the pipeline has already reported success. It should instead run before the S3 deployment, e.g., as a custom action or within the build stage.

  • ✓

    Modify the buildspec in the build stage to include commands that run security scanning tools.

    Why this is correct

    The buildspec.yml file in the CodeBuild stage executes an ordered shell script with any CLI tools you choose; adding a scanner command like `npm audit` or `snyk test` and ensuring it returns a non-zero exit code on failure causes the build action to fail, preventing the artifact from being created. Because the build stage runs before the deploy action, this is a lightweight, fully supported way to embed a security gate without adding a third-party action provider. You must install the scanning binary in the build image or as a build phase dependency.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.