DOP-C02 SDLC Automation Practice Question
Exhibit
CodePipeline execution details: - Source: CodeCommit (branch: main) - Build: CodeBuild (buildspec.yml) - Deploy: CloudFormation (template.yml) - Status: Failed at Deploy stage - Error message: "The following resource(s) failed to create: [MyLambdaFunction]. WaitCondition received 1 unique messages. UniqueId count: 1. Received: 'CREATE_FAILED'" - CloudFormation stack events: "Resource creation cancelled" for a Lambda function with a VPC configuration. - Build logs show: "npm install succeeded, tests passed"
Refer to the exhibit. A CodePipeline deployment fails at the CloudFormation stage. The Lambda function creation is cancelled. What is the MOST likely cause?
⚠ Common exam trap
The trap is that candidates often attribute the failure to a lack of internet access (NAT gateway/VPC endpoints) or to the buildspec, but the actual cause is that the Lambda execution role is missing the required EC2 permissions to create network interfaces inside the VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function's execution role lacks permissions to create ENIs.
When a Lambda function is configured in a VPC, the Lambda service must create an Elastic Network Interface (ENI) in the VPC on behalf of the function. The function's execution role must have permissions for ec2:CreateNetworkInterface, ec2:DescribeNetworkInterfaces, and ec2:DeleteNetworkInterface. Without these permissions, the Lambda service cannot create the ENI, and the Lambda function creation fails. A missing NAT gateway or VPC endpoints only affects internet access for the running function, not the creation process. Therefore, Option C is the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The buildspec.yml file contains an invalid command.
Why it's wrong here
The AWS CodeBuild build stage completes successfully, as evidenced by the build logs showing a successful build. If the buildspec contained an invalid command or syntax error, the build phase would fail before progressing to deployment. Since the pipeline proceeds past the build stage, the buildspec is not the source of the deployment failure.
- ✗
The Lambda function is configured in a VPC without a NAT gateway or VPC endpoints, causing deployment timeout.
Why it's wrong here
When a Lambda function is attached to a VPC without a public IP or NAT gateway, it has no route to the internet to fetch dependencies or call external APIs during initialization. The CodePipeline deployment action uses a Lambda-backed custom resource that must signal success; without network access, it times out, failing the deployment. Adding a NAT gateway or VPC endpoints (e.g., for S3, DynamoDB) resolves this timeout.
- ✓
The Lambda function's execution role lacks permissions to create ENIs.
Why this is correct
If the Lambda execution role were missing ec2:CreateNetworkInterface or related ENI permissions, the Lambda service would fail to create an elastic network interface during function initialization, producing a different error such as 'InvalidParameterValueException' or a resource creation failure. This would prevent the function from running at all, rather than causing a timeout on the deployment's wait condition. Since the observed failure is a timeout, the role likely has the required ENI permissions, but the network route is missing.
- ✗
The CodeCommit branch is not configured correctly in the pipeline.
Why it's wrong here
The source stage in the pipeline uses a specific branch from the CodeCommit repository, and if that branch name were incorrect, the source action would fail to pull the code. The exhibit shows the source stage succeeded, confirming that the branch configuration is valid and the artifact was retrieved. Therefore, the branch setting is not responsible for the deployment stage failure, which occurs later in the pipeline.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CloudFormation to create a stack with a Lambda function that uses a VPC. The stack creation fails with 'CREATE_FAILED: The provided execution role does not have permissions to call ec2:CreateNetworkInterface on the resource'. What is the likely cause?
hard- A.The VPC does not have a subnet with internet access.
- B.The CloudFormation template does not specify a security group.
- C.The Lambda function code has a syntax error.
- ✓ D.The Lambda execution role is missing the ec2:CreateNetworkInterface permission.
Why D: When a Lambda function is configured to run inside a VPC, it requires the `ec2:CreateNetworkInterface` permission to create an Elastic Network Interface (ENI) in the VPC subnets. The error message explicitly states that the execution role lacks this permission, which is a required IAM action for VPC-enabled Lambda functions. Without this permission, CloudFormation cannot provision the ENI, causing the stack creation to fail.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.