DOP-C02 SDLC Automation Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"codebuild:StartBuild",
"codebuild:BatchGetBuilds"
],
"Resource": "arn:aws:codebuild:us-east-1:123456789012:project/my-project"
},
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject"
],
"Resource": "arn:aws:s3:::my-artifact-bucket/*"
}
]
}
```Refer to the exhibit. An IAM policy is attached to a CodeBuild service role. The CodeBuild project is used to build code from a CodeCommit repository and output artifacts to an S3 bucket. However, the build fails with an error: 'Unable to download source from CodeCommit'. What is the missing permission?
⚠ Common exam trap
A common mix-up: candidates confuse the source download phase with the artifact upload phase, assuming the error is about S3 write permissions or KMS decryption, when the error message explicitly identifies the source download as the failing step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permissions to read from the CodeCommit repository.
The error 'Unable to download source from CodeCommit' indicates that the CodeBuild service role lacks the necessary permissions to read the source code from the CodeCommit repository. CodeBuild uses the service role to interact with CodeCommit via Git, which requires the `codecommit:GitPull` action (or broader read permissions like `codecommit:Get*` and `codecommit:List*`). Without these permissions, the build process cannot clone or fetch the source code, causing the failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Permissions to read from the CodeCommit repository.
Why this is correct
To download source code from an AWS CodeCommit repository, the IAM role assumed by CodeBuild must include the codecommit:GitPull action (and typically codecommit:GitClone for TLS/SSH operations). Without this read permission, CodeBuild fails during the source download phase with an error such as 'Not authorized to perform codecommit:GitPull' because the service role cannot access the repository. Neither S3 nor CloudWatch permissions can substitute for the explicit CodeCommit read action, so this is the missing permission in the policy.
- ✗
Permissions to create CloudWatch Logs for build output.
Why it's wrong here
CloudWatch Logs permissions are used by CodeBuild to create log groups or streams and write build output logs after the build commands start running. They are not required for the initial source download phase; the build would fail later when reporting status or logs, not when fetching source from CodeCommit. The absence of logs:PutLogEvents or similar actions would never prevent a GitPull from CodeCommit, so this is not the missing permission causing the source download failure.
- ✗
Permissions to decrypt the KMS key used to encrypt artifacts.
Why it's wrong here
KMS decryption permissions are only relevant if the artifact bucket, the source repository, or the build output is encrypted with a customer-managed AWS KMS key. The scenario describes no such encryption key, and CodeCommit source repositories use AWS-managed key encryption by default, which does not require the CodeBuild role to call kms:Decrypt. Even if encryption were involved, the immediate failure during source download points to a missing CodeCommit read action, not a KMS permission issue.
- ✗
Permissions to write to the S3 artifact bucket.
Why it's wrong here
The policy already grants s3:PutObject for the artifact bucket, so the build role can write build outputs to S3. A missing S3 write permission would cause a different failure later—during the artifact upload phase—not when fetching source code. Since the problem is that CodeBuild cannot read from the CodeCommit repository, the missing action is codecommit:GitPull, not another S3-related action. This option is wrong because it describes an already-allowed permission and one that is unrelated to source download.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.