Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

Exhibit

CodePipeline execution details:
- Source: CodeCommit (branch: main)
- Build: CodeBuild (buildspec.yml)
- Deploy: CloudFormation (template.yml)
- Status: Failed at Deploy stage
- Error message: "The following resource(s) failed to create: [MyLambdaFunction]. WaitCondition received 1 unique messages. UniqueId count: 1. Received: 'CREATE_FAILED'"
- CloudFormation stack events: "Resource creation cancelled" for a Lambda function with a VPC configuration.
- Build logs show: "npm install succeeded, tests passed"

Refer to the exhibit. A CodePipeline deployment fails at the CloudFormation stage. The Lambda function creation is cancelled. What is the MOST likely cause?

⚠ Common exam trap

The trap is that candidates often attribute the failure to a lack of internet access (NAT gateway/VPC endpoints) or to the buildspec, but the actual cause is that the Lambda execution role is missing the required EC2 permissions to create network interfaces inside the VPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda function's execution role lacks permissions to create ENIs.

When a Lambda function is configured in a VPC, the Lambda service must create an Elastic Network Interface (ENI) in the VPC on behalf of the function. The function's execution role must have permissions for ec2:CreateNetworkInterface, ec2:DescribeNetworkInterfaces, and ec2:DeleteNetworkInterface. Without these permissions, the Lambda service cannot create the ENI, and the Lambda function creation fails. A missing NAT gateway or VPC endpoints only affects internet access for the running function, not the creation process. Therefore, Option C is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The buildspec.yml file contains an invalid command.

    Why it's wrong here

    The AWS CodeBuild build stage completes successfully, as evidenced by the build logs showing a successful build. If the buildspec contained an invalid command or syntax error, the build phase would fail before progressing to deployment. Since the pipeline proceeds past the build stage, the buildspec is not the source of the deployment failure.

  • ✗

    The Lambda function is configured in a VPC without a NAT gateway or VPC endpoints, causing deployment timeout.

    Why it's wrong here

    When a Lambda function is attached to a VPC without a public IP or NAT gateway, it has no route to the internet to fetch dependencies or call external APIs during initialization. The CodePipeline deployment action uses a Lambda-backed custom resource that must signal success; without network access, it times out, failing the deployment. Adding a NAT gateway or VPC endpoints (e.g., for S3, DynamoDB) resolves this timeout.

  • ✓

    The Lambda function's execution role lacks permissions to create ENIs.

    Why this is correct

    If the Lambda execution role were missing ec2:CreateNetworkInterface or related ENI permissions, the Lambda service would fail to create an elastic network interface during function initialization, producing a different error such as 'InvalidParameterValueException' or a resource creation failure. This would prevent the function from running at all, rather than causing a timeout on the deployment's wait condition. Since the observed failure is a timeout, the role likely has the required ENI permissions, but the network route is missing.

  • ✗

    The CodeCommit branch is not configured correctly in the pipeline.

    Why it's wrong here

    The source stage in the pipeline uses a specific branch from the CodeCommit repository, and if that branch name were incorrect, the source action would fail to pull the code. The exhibit shows the source stage succeeded, confirming that the branch configuration is valid and the artifact was retrieved. Therefore, the branch setting is not responsible for the deployment stage failure, which occurs later in the pipeline.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS CloudFormation to create a stack with a Lambda function that uses a VPC. The stack creation fails with 'CREATE_FAILED: The provided execution role does not have permissions to call ec2:CreateNetworkInterface on the resource'. What is the likely cause?

hard
  • A.The VPC does not have a subnet with internet access.
  • B.The CloudFormation template does not specify a security group.
  • C.The Lambda function code has a syntax error.
  • ✓ D.The Lambda execution role is missing the ec2:CreateNetworkInterface permission.

Why D: When a Lambda function is configured to run inside a VPC, it requires the `ec2:CreateNetworkInterface` permission to create an Elastic Network Interface (ENI) in the VPC subnets. The error message explicitly states that the execution role lacks this permission, which is a required IAM action for VPC-enabled Lambda functions. Without this permission, CloudFormation cannot provision the ENI, causing the stack creation to fail.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.