Refer to the exhibit. The above IAM policy is attached to an IAM role used by a CI/CD pipeline. Which action is this policy allowing?
This is exactly what the policy authorizes: it includes the StartBuild action to begin a build and BatchGetBuilds to retrieve detailed information about those builds, with the Resource set to the specific CodeBuild project ARN shown in the exhibit. The policy therefore grants the minimum permissions needed to start and observe builds for only that one project.
Why this answer
The IAM policy grants `codebuild:StartBuild` and `codebuild:BatchGetBuilds` actions, which allow starting a build and viewing build details respectively. The `Resource` element restricts these permissions to the specific CodeBuild project `arn:aws:codebuild:us-east-1:123456789012:project/my-project`. Therefore, the policy allows starting and viewing builds for that single project, not any project in the account.
Exam trap
The trap here is that candidates see `codebuild:StartBuild` and `codebuild:BatchGetBuilds` and assume they apply to all projects, overlooking the resource ARN restriction that limits the policy to a single project.
How to eliminate wrong answers
Option A is wrong because `codebuild:StartBuild` is allowed only for the specified project ARN, not for all projects (`*`). Option B is wrong because `codebuild:BatchGetBuilds` is also scoped to the single project ARN, so it does not grant viewing details of any build in the account. Option D is wrong because the policy does not include actions like `codebuild:CreateProject` or `codebuild:UpdateProject`; it only covers starting and viewing builds.