Courseiva

DOP-C02 · topic practice

SDLC Automation practice questions

SDLC Automation is 22% of DOP-C02 and covers CI/CD pipelines, deployment strategies, and release management on AWS. The exam tests this through scenario questions where you must choose CodePipeline, CodeBuild, CodeDeploy, or CloudFormation configurations, interpret buildspec and appspec files, and select safe deployment or rollback behaviour under constraints.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: SDLC Automation

What the exam tests

What to know about SDLC Automation

You must wire CodePipeline stages with CodeBuild buildspec.yml and CodeDeploy appspec.yml to automate builds and releases. Get the deployment strategy right: choose CodeDeploy blue/green or canary with proper AppSpec hooks and rollback alarms.

Configuring CodePipeline stages, actions, cross-region/cross-account artifact stores and manual approval gates

Writing CodeBuild buildspec.yml phases, artifacts, cache, and environment variables with Parameter Store or Secrets Manager

Choosing CodeDeploy deployment types: in-place vs blue/green, EC2/ECS/Lambda hooks and appspec lifecycle events

Using CloudFormation change sets, stack policies, and CodeDeploy rollback triggers for safe release automation

Watch out for

Common SDLC Automation exam traps

  • ▸Assuming CodePipeline automatically rolls back a failed deployment; rollback requires CodeDeploy alarms or manual retry configuration
  • ▸Confusing CodeDeploy appspec hooks like BeforeInstall and AfterAllowTraffic, applying them to the wrong compute platform lifecycle
  • ▸Forgetting that CodeBuild artifacts must be declared in buildspec and passed via pipeline input/output artifacts to reach later stages

Practice set

SDLC Automation questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full SDLC Automation explanation →

A company uses AWS CodePipeline with a multi-branch strategy. A new feature branch triggers a pipeline that runs unit tests and deploys to a test environment. The deployment step uses AWS CodeDeploy with a deployment group configured for in-place deployment to Amazon EC2 instances. The deployment fails intermittently with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The instances are healthy and pass health checks. What is the most likely cause?

A DevOps team is designing a CI/CD pipeline for a microservices application. Each microservice has its own code repository and build artifacts. The team wants to use AWS CodePipeline with multiple parallel actions to build and test all microservices simultaneously. They also want to ensure that if one microservice's build fails, the pipeline does not block other microservices. Which THREE steps should the team take? (Choose THREE.)

Question 3mediummultiple choice
Review the full subnetting walkthrough →

A company uses AWS CodeBuild to compile a Java application. The buildspec.yml includes a 'pre_build' phase that runs SonarQube for static code analysis. The analysis requires access to a private SonarQube server hosted on an EC2 instance in the same VPC. The CodeBuild project is configured with a VPC ID, subnet IDs, and security group IDs. However, the build fails with a timeout when trying to connect to the SonarQube server. The security group for the SonarQube server allows inbound traffic on port 9000 from the CodeBuild security group. What is the MOST likely reason for the failure?

Question 4mediummultiple choice
Read the full SDLC Automation explanation →

A company uses AWS CodePipeline with Amazon S3 as the source stage. The pipeline triggers on object creation events in the S3 bucket. The development team notices that the pipeline does not trigger when multiple files are uploaded simultaneously. What is the most likely cause?

A DevOps engineer is managing a CI/CD pipeline using AWS CodePipeline with multiple stages: Source (CodeCommit), Build (CodeBuild), Test (CodeBuild), and Deploy (CodeDeploy). The engineer wants to add manual approval steps before the Test and Deploy stages. Additionally, the pipeline should automatically roll back the deployment if the Deploy stage fails. Which two actions should the engineer take to implement these requirements? (Choose two.)

Match each AWS deployment strategy to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Two identical environments; traffic switches after validation

Incremental rollout to a small subset before full release

Updates instances in batches to minimize downtime

Replaces entire instances with new ones; no in-place changes

Deploys to all instances simultaneously (fastest but riskier)

Question 7mediummultiple choice
Read the full SDLC Automation explanation →

A company uses AWS CodePipeline to orchestrate a multi-stage deployment. The pipeline has a source, build, test, and deploy stage. The test stage runs integration tests against a temporary environment. The team wants to ensure that the deploy stage only runs if the test stage succeeds. What configuration is needed?

Question 8mediummultiple choice
Read the full SDLC Automation explanation →

A CloudFormation stack creation failed as shown in the exhibit. What is the MOST likely cause of the failure?

Network Topology
$ aws cloudformation describe-stack-eventsstack-name MyStackRefer to the exhibit."StackEvents": ["StackId": "arn:aws:cloudformation:us-east-1:123456789012:stack/MyStack/abc123","EventId": "Event-1","StackName": "MyStack","LogicalResourceId": "MyStack","PhysicalResourceId": "arn:aws:cloudformation:us-east-1:123456789012:stack/MyStack/abc123","ResourceType": "AWS::CloudFormation::Stack","Timestamp": "2024-01-15T10:00:00.000Z","ResourceStatus": "CREATE_IN_PROGRESS"},"EventId": "Event-2","LogicalResourceId": "MyVPC","PhysicalResourceId": "vpc-12345678","ResourceType": "AWS::EC2::VPC","Timestamp": "2024-01-15T10:01:00.000Z","ResourceStatus": "CREATE_COMPLETE""EventId": "Event-3","LogicalResourceId": "MySubnet","PhysicalResourceId": "subnet-12345678","ResourceType": "AWS::EC2::Subnet","Timestamp": "2024-01-15T10:02:00.000Z","ResourceStatus": "CREATE_FAILED",
Question 9mediummultiple choice
Read the full SDLC Automation explanation →

A company uses AWS CodeCommit as a Git repository. Developers want to enforce that all commits are signed with GPG keys. How can this be achieved?

Question 10easymultiple choice
Read the full SDLC Automation explanation →

A DevOps engineer needs to automatically roll back a CodeDeploy deployment if the number of failed instances exceeds a threshold. Which deployment configuration should be used?

Which THREE steps are required to set up cross-account access for AWS CodePipeline using a customer-managed KMS key?

Question 12mediummultiple choice
Read the full SDLC Automation explanation →

Refer to the exhibit. A DevOps engineer runs this AWS CLI command to list all CodeBuild projects with 'production' in their name. The command returns an empty list, but the engineer knows there are projects named 'production-app' and 'production-backend'. What is the most likely reason?

Network Topology
aws codebuild list-projectsquery "projects[?contains(@, 'production')]"region us-east-1Refer to the exhibit.
Question 13hardmultiple choice
Read the full SDLC Automation explanation →

Refer to the exhibit. A CloudFormation template creates a Lambda function. After deployment, the function fails with a timeout error. Logs are not being created in CloudWatch. What is the most likely cause?

Exhibit

Refer to the exhibit.

Resources:
  MyLambdaFunction:
    Type: AWS::Lambda::Function
    Properties:
      Code:
        S3Bucket: my-bucket
        S3Key: function.zip
      Handler: index.handler
      Role: !GetAtt LambdaExecutionRole.Arn
      Runtime: python3.9
  LambdaExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              Service: lambda.amazonaws.com
            Action: sts:AssumeRole
      Policies:
        - PolicyName: LambdaPolicy
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action: logs:CreateLogGroup
                Resource: arn:aws:logs:us-east-1:123456789012:*
              - Effect: Allow
                Action: logs:CreateLogStream
                Resource: arn:aws:logs:us-east-1:123456789012:*
              - Effect: Allow
                Action: logs:PutLogEvents
                Resource: arn:aws:logs:us-east-1:123456789012:*
Question 14mediummultiple choice
Read the full SDLC Automation explanation →

A company uses AWS CodeCommit and wants to enforce that all commits to the main branch are signed. What must be configured to enforce this requirement?

A DevOps team uses AWS CloudFormation to manage infrastructure. They want to implement a change management process that requires approval before making changes to production stacks. Which TWO approaches can be used to enforce this?

Question 16mediummultiple choice
Read the full SDLC Automation explanation →

An IAM policy is attached to a user who needs to manually start a CodePipeline execution. The pipeline uses an S3 bucket named 'my-artifact-bucket' for artifacts. The user reports that they cannot start the pipeline. Which action is missing from the policy?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "codepipeline:StartPipelineExecution",
        "codepipeline:GetPipeline"
      ],
      "Resource": "arn:aws:codepipeline:us-east-1:123456789012:MyPipeline"
    },
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject"
      ],
      "Resource": "arn:aws:s3:::my-artifact-bucket/*"
    }
  ]
}
```
Question 17hardmultiple choice
Read the full SDLC Automation explanation →

A team uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. During a stack update, they need to modify the DB instance class but want to avoid downtime. Which update policy should they use?

Question 18mediummultiple choice
Read the full SDLC Automation explanation →

Refer to the exhibit. An IAM policy is attached to a user. The user reports that they cannot push to the 'MyRepo' repository. What is the likely reason?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "codecommit:GitPull",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "codecommit:GitPush",
      "Resource": "arn:aws:codecommit:us-east-1:123456789012:MyRepo"
    }
  ]
}
Question 19mediummultiple choice
Read the full SDLC Automation explanation →

Refer to the exhibit. A DevOps engineer runs the AWS CLI command to list deployments for an application. The output shows only 2 deployments, but the team knows there are more. How can the engineer retrieve the remaining deployments?

Network Topology
$ aws deploy list-deploymentsapplication-name MyAppdeployment-group-name MyDGmax-items 5Refer to the exhibit."deployments": ["d-ABCDEFGHI","d-JKLMNOPQR"],"nextToken": "abc123"
Question 20mediummultiple choice
Read the full SDLC Automation explanation →

An organization uses AWS CodeBuild to run integration tests. The tests require a large amount of memory and CPU, and they often timeout after the default 60 minutes. What is the MOST efficient way to increase the timeout and allocate more resources?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused SDLC Automation sessions

Start a SDLC Automation only practice session

Every question in these sessions is drawn from the SDLC Automation domain — nothing else.

Related practice questions

Related DOP-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the DOP-C02 exam test about SDLC Automation?
You must wire CodePipeline stages with CodeBuild buildspec.yml and CodeDeploy appspec.yml to automate builds and releases. Get the deployment strategy right: choose CodeDeploy blue/green or canary with proper AppSpec hooks and rollback alarms.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just SDLC Automation questions in a focused session?
Yes — the session launcher on this page draws every question from the SDLC Automation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other DOP-C02 topics?
Use the topic links above to move to related areas, or go back to the DOP-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the DOP-C02 exam covers. They are not copied from any real exam or dump site.