Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

Exhibit

Refer to the exhibit.

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "codebuild:StartBuild",
                "codebuild:BatchGetBuilds"
            ],
            "Resource": "arn:aws:codebuild:us-east-1:123456789012:project/my-project"
        },
        {
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:PutObject"
            ],
            "Resource": "arn:aws:s3:::my-artifact-bucket/*"
        }
    ]
}
```

Refer to the exhibit. An IAM policy is attached to a CodeBuild service role. The CodeBuild project is used to build code from a CodeCommit repository and output artifacts to an S3 bucket. However, the build fails with an error: 'Unable to download source from CodeCommit'. What is the missing permission?

⚠ Common exam trap

A common mix-up: candidates confuse the source download phase with the artifact upload phase, assuming the error is about S3 write permissions or KMS decryption, when the error message explicitly identifies the source download as the failing step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Permissions to read from the CodeCommit repository.

The error 'Unable to download source from CodeCommit' indicates that the CodeBuild service role lacks the necessary permissions to read the source code from the CodeCommit repository. CodeBuild uses the service role to interact with CodeCommit via Git, which requires the `codecommit:GitPull` action (or broader read permissions like `codecommit:Get*` and `codecommit:List*`). Without these permissions, the build process cannot clone or fetch the source code, causing the failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Permissions to read from the CodeCommit repository.

    Why this is correct

    To download source code from an AWS CodeCommit repository, the IAM role assumed by CodeBuild must include the codecommit:GitPull action (and typically codecommit:GitClone for TLS/SSH operations). Without this read permission, CodeBuild fails during the source download phase with an error such as 'Not authorized to perform codecommit:GitPull' because the service role cannot access the repository. Neither S3 nor CloudWatch permissions can substitute for the explicit CodeCommit read action, so this is the missing permission in the policy.

  • ✗

    Permissions to create CloudWatch Logs for build output.

    Why it's wrong here

    CloudWatch Logs permissions are used by CodeBuild to create log groups or streams and write build output logs after the build commands start running. They are not required for the initial source download phase; the build would fail later when reporting status or logs, not when fetching source from CodeCommit. The absence of logs:PutLogEvents or similar actions would never prevent a GitPull from CodeCommit, so this is not the missing permission causing the source download failure.

  • ✗

    Permissions to decrypt the KMS key used to encrypt artifacts.

    Why it's wrong here

    KMS decryption permissions are only relevant if the artifact bucket, the source repository, or the build output is encrypted with a customer-managed AWS KMS key. The scenario describes no such encryption key, and CodeCommit source repositories use AWS-managed key encryption by default, which does not require the CodeBuild role to call kms:Decrypt. Even if encryption were involved, the immediate failure during source download points to a missing CodeCommit read action, not a KMS permission issue.

  • ✗

    Permissions to write to the S3 artifact bucket.

    Why it's wrong here

    The policy already grants s3:PutObject for the artifact bucket, so the build role can write build outputs to S3. A missing S3 write permission would cause a different failure later—during the artifact upload phase—not when fetching source code. Since the problem is that CodeBuild cannot read from the CodeCommit repository, the missing action is codecommit:GitPull, not another S3-related action. This option is wrong because it describes an already-allowed permission and one that is unrelated to source download.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.