Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 CodeCommit pre-receive hook GPG Practice Question

A company uses AWS CodeCommit as a source repository and wants to enforce that all commits are signed using GPG keys. The DevOps team configures a pre-receive hook in CodeCommit to validate commit signatures. However, the hook rejects all commits even when valid GPG signatures are present. What is the most likely cause?

⚠ Common exam trap

Many candidates confuse CodeCommit with self-managed Git platforms (like GitHub or GitLab) that support pre-receive hooks, leading them to assume CodeCommit also supports this feature, when in fact CodeCommit uses a different enforcement mechanism (repository-level settings and IAM policies).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CodeCommit does not support pre-receive hooks.

AWS CodeCommit does not support pre-receive hooks. Pre-receive hooks are a feature of self-managed Git repositories (e.g., GitHub Enterprise, GitLab, or on-premises Git servers) that run on the server before accepting a push. CodeCommit uses IAM policies and repository-level settings (such as requiring signed commits via the 'git push --signed' flag) to enforce commit signing, not server-side hooks. Therefore, any attempt to configure a pre-receive hook in CodeCommit will fail, causing all commits to be rejected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The GPG key is not registered with the IAM user's profile.

    Why it's wrong here

    The absence of a GPG key from an IAM user's profile affects commit signing, not server-side hook execution. CodeCommit uses IAM to associate public GPG keys so clients can sign commits, but because CodeCommit never runs pre-receive hooks, a missing GPG key cannot produce a pre-receive hook error. Even if commit signing is required, hook processing is not part of the push path.

  • ✓

    CodeCommit does not support pre-receive hooks.

    Why this is correct

    This is correct. CodeCommit is a managed Git service that does not expose a file system or a server-side Git hooks directory, so Git's pre-receive hook scripts are not supported. Instead, CodeCommit offers repository triggers (SNS/Lambda) and notification rules, which are evaluated after the push is accepted. Therefore, any apparent pre-receive hook failure cannot actually occur in CodeCommit.

  • ✗

    The hook script has a syntax error.

    Why it's wrong here

    A syntax error in a hook script would only be relevant if the repository ran the script, but CodeCommit has no pre-receive hook execution. Hook scripts are not uploaded to the repository, so there is no script to be rejected. This explanation incorrectly assumes that CodeCommit behaves like a self-managed Git server, such as an EC2 instance hosting a bare Git repository with hooks enabled.

  • ✗

    The repository is not configured to require signed commits.

    Why it's wrong here

    CodeCommit does integrate with IAM to support GPG-signed commits, but the repository itself does not have a built-in 'require signed commits' toggle that can enforce signatures before a push lands. Enforcing signed commits would typically be done with a client-side hook or an external IAM condition, not a server-side pre-receive hook. Since CodeCommit does not support pre-receive hooks, repository signing configuration is irrelevant to the reported failure.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The DOP-C02 exam frequently reuses these exact scenarios with slightly different constraints.

✓CodeCommit does not support pre-receive hooks.Correct answer▾

Why this is correct

This is correct. CodeCommit is a managed Git service that does not expose a file system or a server-side Git hooks directory, so Git's pre-receive hook scripts are not supported. Instead, CodeCommit offers repository triggers (SNS/Lambda) and notification rules, which are evaluated after the push is accepted. Therefore, any apparent pre-receive hook failure cannot actually occur in CodeCommit.

✗The GPG key is not registered with the IAM user's profile.Wrong answer — click to see why▾

Why this is wrong here

While GPG key must be associated with the IAM user, the issue is that CodeCommit doesn't support pre-receive hooks.

✗The hook script has a syntax error.Wrong answer — click to see why▾

Why this is wrong here

Even if the script is correct, CodeCommit does not execute pre-receive hooks.

✗The repository is not configured to require signed commits.Wrong answer — click to see why▾

Why this is wrong here

CodeCommit does not have a built-in setting to require signed commits; the hook is the intended mechanism, but it's not supported.

Analysis generated from the official DOP-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.