Courseiva
SDLC Automation →hardMultiple Select

Secure Manual Approval in CodePipeline

A company uses AWS CodePipeline to deploy a critical application. The pipeline has a manual approval step before deployment. Which TWO actions should be taken to improve security and auditability? (Choose two.)

⚠ Common exam trap

Many exam-takers think automated approvals (Option D) are always more secure, but the question specifically asks for improving security and auditability of a manual approval step, and removing human oversight actually reduces security for critical deployments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail to log all approval actions.

Enabling AWS CloudTrail to log all approval actions provides a detailed, immutable audit trail of who approved or rejected a pipeline stage, when it happened, and from which IP address. This is essential for compliance and forensic analysis, as CloudTrail captures the `Approval` API calls made by CodePipeline, including the `approve` and `reject` actions, along with the IAM user or role identity. Without CloudTrail, there is no native logging of manual approval events, making it impossible to prove accountability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable AWS CloudTrail to log all approval actions.

    Why this is correct

    Enabling AWS CloudTrail records the PutApprovalResult API calls made through CodePipeline when an approver clicks Approve or Reject. CloudTrail logs the IAM principal or federated user identity, the timestamp, the source IP address, and the decision, providing an immutable audit trail that satisfies compliance and forensic needs. This is the correct answer because the company's explicit requirement is to know who approved the deployment and when.

  • ✗

    Remove the approval step and rely on post-deployment monitoring.

    Why it's wrong here

    Removing the approval stage eliminates the human verification control that the company requires before a critical application is deployed. Post-deployment monitoring, such as Amazon CloudWatch alarms, can only detect failures and anomalies after the release has already shipped, meaning a faulty build can affect end users and trigger rollbacks or incident response. This does not provide the pre-production authorization gate that a manual approval enforces, so it violates the stated control objective.

  • ✓

    Integrate with AWS IAM to require multi-factor authentication (MFA) for approvers.

    Why this is correct

    Requiring MFA for approvers via an IAM policy condition such as aws:MultiFactorAuthPresent ensures that the PutApprovalResult call is made only after the user proves possession of a second authentication factor. This mitigates the risk of stolen or reused passwords because a password alone is insufficient to authorize the deployment. While this does not directly log who approved, it strengthens authentication for the sensitive approval action and is an appropriate security enhancement.

  • ✗

    Replace the manual approval with an automated approval based on test results.

    Why it's wrong here

    An automated approval driven by test results replaces the required human judgment with a predetermined rule, so it does not meet the explicit 'manual approval' requirement. Even if tests pass, a human approver may need to consider deployment windows, rollback readiness, incident status, or other context that automated gates ignore. Thus it changes the nature of the control rather than enhancing its auditability or accountability.

  • ✗

    Use a shared IAM user for all approvers to simplify management.

    Why it's wrong here

    Using a shared IAM user for all approvers prevents CloudTrail or IAM Access Analyzer from attributing an approval event to a specific individual, breaking non-repudiation and making post-incident reviews impossible. It also violates the principle of least privilege because any approver who knows the credentials can perform any future approval, and it increases the blast radius if those credentials are compromised. Individual IAM users or federated identities with MFA should be used so that each approval decision is uniquely attributable.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.