DOP-C02 SDLC Automation Practice Question
Which TWO actions should a DevOps engineer take to ensure that an AWS CodeBuild project's artifacts are automatically deployed to an Amazon S3 bucket with server-side encryption using AWS KMS? (Choose 2.)
⚠ Common exam trap
Test-takers frequently confuse default bucket encryption (Option D) with explicit artifact encryption in CodeBuild, not realizing that CodeBuild's buildspec encryption settings override bucket defaults and that the service role must have explicit KMS key permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the buildspec.yaml, set the 'artifacts' section to include 'encryptionDisabled: false' and specify the KMS key ID.
Setting 'encryptionDisabled: false' in the buildspec.yaml artifacts section explicitly enables encryption for the build output, and specifying the KMS key ID ensures that the artifacts are encrypted with that specific AWS KMS key. This configuration directly instructs CodeBuild to use server-side encryption with AWS KMS when uploading artifacts to S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable versioning on the S3 bucket.
Why it's wrong here
S3 versioning preserves multiple versions of an object to protect against accidental deletion or overwrites, but it has no effect on how data is encrypted at rest. Enabling versioning does not enforce server-side encryption; CodeBuild can still upload artifacts without encryption, so this action does not satisfy the requirement to encrypt build artifacts.
- ✗
Configure the S3 bucket policy to require HTTPS for all uploads.
Why it's wrong here
Requiring HTTPS via a bucket policy condition such as aws:SecureTransport enforces encryption in transit for all uploads and downloads, but it does not mandate encryption at rest. The policy only protects data while it is in flight; once stored, the artifact may remain in plaintext. Since the requirement is about SSE-KMS encryption, this action is insufficient.
- ✓
In the buildspec.yaml, set the 'artifacts' section to include 'encryptionDisabled: false' and specify the KMS key ID.
Why this is correct
In the buildspec.yaml, the artifacts section can set 'encryptionDisabled: false' and specify the desired KMS key ID via the 'kmsKeyId' setting (or similarly named property). This explicitly instructs CodeBuild to encrypt the output artifact using the specified customer-managed KMS key, ensuring server-side encryption at rest. This is the direct and reliable way to enforce SSE-KMS for build artifacts.
- ✗
Enable default encryption on the S3 bucket using SSE-KMS.
Why it's wrong here
S3 default encryption with SSE-KMS only applies when an upload does not include encryption headers. CodeBuild may specify its own encryption settings (or none), which can override the bucket's default encryption. Since the requirement is to guarantee encryption with a specific KMS key, relying on default encryption is not deterministic; the buildspec must explicitly configure encryption.
- ✓
Grant the CodeBuild service role permission to use the KMS key via the key policy.
Why this is correct
The CodeBuild service role must be permitted by the KMS key policy to perform kms:GenerateDataKey and kms:Decrypt operations. Without these permissions, CodeBuild cannot use the KMS key to encrypt the artifact, even if the buildspec explicitly requests it. Granting this access is a necessary prerequisite for the buildspec encryption configuration to succeed.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.