DOP-C02 SDLC Automation Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "codedeploy:*",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"autoscaling:CompleteLifecycleAction",
"autoscaling:DescribeLifecycleHooks",
"autoscaling:RecordLifecycleActionHeartbeat"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "iam:PassRole",
"Resource": "arn:aws:iam::123456789012:role/CodeDeployServiceRole"
}
]
}Refer to the exhibit. A DevOps engineer created this IAM policy for a CodeDeploy service role. The deployment fails with an 'AccessDenied' error when attempting to register instances with an Auto Scaling group. What is the likely cause?
⚠ Common exam trap
Watch out — candidates often assume the error is due to missing lifecycle hook permissions (Option A) or a trust relationship issue (Option B), but the actual cause is the lack of specific Auto Scaling write permissions required for instance registration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy is missing autoscaling:UpdateAutoScalingGroup and autoscaling:SetDesiredCapacity.
The CodeDeploy service role must include permissions for autoscaling:UpdateAutoScalingGroup and autoscaling:SetDesiredCapacity to allow CodeDeploy to register instances with an Auto Scaling group during a deployment. Without these actions, the deployment fails with an 'AccessDenied' error when CodeDeploy attempts to attach instances to the Auto Scaling group or adjust its capacity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy does not allow autoscaling:CompleteLifecycleAction.
Why it's wrong here
While CompleteLifecycleAction is a legitimate Auto Scaling API call used to complete a lifecycle hook, CodeDeploy does not rely on lifecycle hooks for its standard deployment flow. The policy's existing Auto Scaling permissions already include DescribeAutoScalingGroups and other read-only operations, but the deployment failure stems from missing write permissions to modify group capacity. Thus, adding CompleteLifecycleAction would not resolve the missing permission issue.
- ✗
The role is not trusted by the EC2 service.
Why it's wrong here
This IAM role is intended for CodeDeploy to assume, not EC2, so its trust policy should list codedeploy.amazonaws.com as the trusted principal. If the trust relationship were incorrectly set to EC2, the CodeDeploy service would be unable to assume the role at all, whereas here the failure occurs after the role is successfully assumed. Therefore, the role's trust policy is not the problem.
- ✗
The iam:PassRole action is not scoped to the correct resource.
Why it's wrong here
The iam:PassRole statement in the policy is properly limited to the exact Role ARN that CodeDeploy needs to pass, thereby satisfying AWS's PassRole requirements. Even if the action were absent, CodeDeploy would not have the authority to attach the role, but because it is correctly scoped, this is not the cause of the error. The actual deficiency lies in Auto Scaling management permissions, not PassRole.
- ✓
The policy is missing autoscaling:UpdateAutoScalingGroup and autoscaling:SetDesiredCapacity.
Why this is correct
For a deployment to an Auto Scaling group, CodeDeploy must be able to adjust the group's desired capacity and update its configuration. autoscaling:UpdateAutoScalingGroup lets CodeDeploy modify min/max/desired values, while autoscaling:SetDesiredCapacity forces the group to scale to the exact instance count required for the deployment. Without these permissions, CodeDeploy cannot perform instance replacement or blue/green transitions, causing the deployment to fail.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.