Which TWO actions can be used to improve the security of a CI/CD pipeline that uses AWS CodePipeline? (Choose two.)
By enabling default encryption on the S3 bucket used as CodePipeline's artifact store—or specifying an AWS KMS customer-managed key in the pipeline settings—all build outputs and source artifacts are encrypted at rest with either SSE-S3 or SSE-KMS. This protects sensitive data from unauthorized direct access to the bucket, even if the bucket policy or ACL is misconfigured. Using KMS adds an additional layer of control by letting you restrict which roles can decrypt artifacts and enabling CloudTrail auditing of all decrypt operations.
Why this answer
AWS CodePipeline stores artifacts in an S3 bucket, and enabling default encryption (SSE-S3 or SSE-KMS) ensures that all objects at rest are encrypted, protecting sensitive build outputs and source code from unauthorized access if the bucket is compromised. This is a fundamental security best practice for data at rest in any CI/CD pipeline.
Exam trap
The trap here is that candidates often confuse 'simplifying permissions' (Option E) with security best practices, but the DOP-C02 exam emphasizes least privilege and role separation over convenience.