DOP-C02 SDLC Automation Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject"
],
"Resource": "arn:aws:s3:::my-codepipeline-bucket/*"
},
{
"Effect": "Allow",
"Action": [
"codebuild:StartBuild",
"codebuild:BatchGetBuilds"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": "iam:PassRole",
"Resource": "arn:aws:iam::123456789012:role/CodeBuildServiceRole",
"Condition": {
"StringEquals": {
"iam:PassedToService": "codebuild.amazonaws.com"
}
}
}
]
}Refer to the exhibit. An IAM policy is attached to a CodePipeline service role. When the pipeline tries to start a CodeBuild project, it fails with an 'AccessDenied' error. The CodeBuild project uses a different service role (arn:aws:iam::123456789012:role/CodeBuildServiceRole2). What is the MOST likely cause?
⚠ Common exam trap
DOP-C02 often tests the iam:PassRole permission and its role in service-to-service delegation; candidates may overlook that the pipeline role needs explicit PassRole permission for the specific CodeBuild service role, leading to AccessDenied errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy only allows iam:PassRole for a specific role ARN, but the CodeBuild project uses a different role.
When CodePipeline starts a CodeBuild project, it must pass the CodeBuild service role to CodeBuild using iam:PassRole. If the pipeline's service role policy only allows iam:PassRole for a specific role ARN (e.g., CodeBuildServiceRole1) but the CodeBuild project is configured with a different role (CodeBuildServiceRole2), the PassRole action will be denied, causing an AccessDenied error. This is the most likely cause because the error occurs at the start of the build, and the policy explicitly restricts the role that can be passed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy has a condition on the s3 actions that is not satisfied.
Why it's wrong here
S3 conditions govern artifact retrieval, not the StartBuild call, so they cannot produce this AccessDenied. Such conditions matter when the pipeline role reads or writes artifacts in a bucket with restrictive policies; here the failure occurs earlier, at the codebuild:StartBuild and iam:PassRole stage.
- ✗
The policy does not allow codebuild:StartBuild for the specific project.
Why it's wrong here
StartBuild is the correct action name, but the failure stems from the pipeline role lacking iam:PassRole for CodeBuildServiceRole2, which CodeBuild requires when assuming its own service role. The policy's codebuild permissions are not the blocker; PassRole is what authorises handing that role to the build.
- ✗
The policy does not allow s3:GetObject on the artifact bucket.
Why it's wrong here
s3:GetObject is needed for source and artifact downloads, but the pipeline never reaches that stage because StartBuild itself is denied. Missing GetObject would surface as an S3 error during the build, not an AccessDenied when starting the project.
- ✓
The policy only allows iam:PassRole for a specific role ARN, but the CodeBuild project uses a different role.
Why this is correct
The pipeline role's policy scopes `iam:PassRole` to a single resource ARN, so CodePipeline cannot hand CodeBuildServiceRole2 to CodeBuild. Starting a build requires passing the project's service role; the mismatched ARN triggers AccessDenied. Broadening the resource to the intended role ARN resolves it.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.