DOP-C02 SDLC Automation Practice Question
Network Topology
Refer to the exhibit. Why does the build fail?
⚠ Common exam trap
DOP-C02 often tests the misconception that S3 bucket policies or project role association are the cause of permission errors, when the actual issue is missing specific IAM permissions for the service role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CodeBuild role does not have permission to create CloudFront invalidations.
The build fails because the CodeBuild service role lacks the necessary IAM permission to create a CloudFront invalidation. In AWS CodeBuild, the service role must have explicit permissions for all AWS API calls made during the build, including cloudfront:CreateInvalidation. Without this permission, the AWS CLI command to invalidate the CloudFront distribution returns an AccessDenied error, causing the build to fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The CodeBuild role does not have permission to create CloudFront invalidations.
Why this is correct
The error message in the build log explicitly returns AccessDenied for the CreateInvalidation action, which means the IAM role assumed by CodeBuild does not include a statement allowing cloudfront:CreateInvalidation on the target distribution. Even though the role is correctly associated and used, it lacks this specific identity-based permission, so the aws cloudfront create-invalidation API call fails. This is an IAM policy gap, not a misconfiguration of the project or the distribution.
- ✗
The S3 bucket policy denies write access to the CodeBuild role.
Why it's wrong here
The build log shows that the aws s3 sync step completed successfully, which requires s3:PutObject and s3:ListBucket permissions on the destination bucket. If the S3 bucket policy explicitly denied write access to the CodeBuild role, the sync phase would have failed earlier with an AccessDenied error on the S3 operation, not on the subsequent CloudFront invalidation call. Therefore, the bucket policy is not the cause of this failure.
- ✗
The CodeBuild project is not associated with the correct service role.
Why it's wrong here
The build is executing and the environment is using the service role associated with the CodeBuild project; the error occurs during a CloudFront API call that the role is making. If the project were associated with the wrong role, the build would typically fail much earlier—either at environment provisioning or when attempting to access resources such as S3—or the role would lack even the S3 permissions that were clearly applied. The issue is not the association, but an insufficiently scoped permission in the already-assumed role.
- ✗
The CloudFront distribution ID is incorrect.
Why it's wrong here
The error returned is AccessDenied, not NoSuchDistribution or InvalidArgument. If the CloudFront distribution ID were incorrect or nonexistent, the CreateInvalidation API would return an explicit error indicating that the distribution was not found or that the provided ID is invalid. Since the API call reached the authorization stage and was denied due to IAM, the distribution ID itself is valid and recognized; the failure is purely a permissions problem.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.