DOP-C02 Restrict CodePipeline to main branch Practice Question
A DevOps engineer is designing a CI/CD pipeline using AWS CodePipeline. The source stage is AWS CodeCommit, and the build stage uses AWS CodeBuild. The pipeline must only trigger on changes to the main branch. However, the engineer notices that the pipeline is also triggering on changes to feature branches that are merged via pull requests. What configuration change should the engineer make to ensure the pipeline only triggers on direct commits to the main branch?
⚠ Common exam trap
Many candidates confuse the pipeline source stage branch filter (which only affects which branch is used as source code) with the CloudWatch Events rule branch filter (which controls which events actually trigger the pipeline), leading them to incorrectly select option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a branch filter in the CloudWatch Events rule that triggers the pipeline, specifying only the main branch.
AWS CodePipeline pipelines are triggered by CloudWatch Events rules that monitor CodeCommit repository events. By default, the rule may trigger on all branch changes. Adding a branch filter in the CloudWatch Events rule that specifies only the main branch ensures that only direct commits to main trigger the pipeline, ignoring feature branch merges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the CodeCommit repository to disable events for all branches except main.
Why it's wrong here
CodeCommit does not provide a configuration setting to disable repository events on a per-branch basis; push events are emitted globally for all branches. Even if such a setting existed, it would not integrate with the pipeline's event rule, leaving the trigger unaffected. The correct approach is to filter at the CloudWatch Events rule level, not at the repository level.
- ✓
Add a branch filter in the CloudWatch Events rule that triggers the pipeline, specifying only the main branch.
Why this is correct
By adding a branchName filter to the event pattern of the CloudWatch Events (EventBridge) rule that invokes the pipeline, the rule only triggers when a push occurs on the main branch. This is the documented and precise way to restrict executions by branch while still capturing all relevant repository state changes. The filter is evaluated in the event pattern, so other branches don't initiate a pipeline run.
- ✗
Modify the pipeline's source stage to use a branch name filter, which will ignore events from other branches.
Why it's wrong here
The pipeline's source stage specifies a particular repository and branch to pull from, but it does not act as a filter on incoming trigger events; CodePipeline ignores events for the branch defined in the source configuration and simply proceeds when any event activates it. There is no 'ignore events from other branches' concept within the source action. Branch-level triggering must be controlled by the event rule's pattern, not the source configuration.
- ✗
Use a Lambda function as a source action to check the branch before starting the build.
Why it's wrong here
Using a Lambda function as a source action is an unnecessarily heavy pattern: the Lambda would have to perform custom checks and then return source revisions, and you would still need an event rule to invoke it. Moreover, a Lambda source action cannot be triggered directly by CodeCommit events; it is typically polled by CodePipeline. Branch filtering belongs in the event rule, not in custom runtime code.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The DOP-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Add a branch filter in the CloudWatch Events rule that triggers the pipeline, specifying only the main branch.Correct answer▾
Why this is correct
By adding a branchName filter to the event pattern of the CloudWatch Events (EventBridge) rule that invokes the pipeline, the rule only triggers when a push occurs on the main branch. This is the documented and precise way to restrict executions by branch while still capturing all relevant repository state changes. The filter is evaluated in the event pattern, so other branches don't initiate a pipeline run.
✗Configure the CodeCommit repository to disable events for all branches except main.Wrong answer — click to see why▾
Why this is wrong here
CodeCommit does not have a per-branch event setting; events are emitted for all branches.
✗Modify the pipeline's source stage to use a branch name filter, which will ignore events from other branches.Wrong answer — click to see why▾
Why this is wrong here
The branch name in the source action only defines which branch to pull; the trigger event still comes from any branch unless filtered at the event rule.
✗Use a Lambda function as a source action to check the branch before starting the build.Wrong answer — click to see why▾
Why this is wrong here
This is a workaround but not the standard or efficient solution; the event rule filter is simpler.
Analysis generated from the official DOP-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.