Courseiva
SDLC Automation →mediumMultiple Select

DOP-C02 SDLC Automation Practice Question

Which TWO are valid use cases for using AWS CodeArtifact in a CI/CD pipeline? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse CodeArtifact with a general-purpose artifact store, but it is strictly a package manager repository for language-specific packages (npm, Maven, PyPI, NuGet), not for Docker images, source code, or static assets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Caching dependencies from public repositories to improve build speed and reliability.

CodeArtifact can act as a proxy cache for public repositories like npm, PyPI, Maven, and NuGet. By caching dependencies locally, it reduces reliance on external sources, improves build speed by avoiding repeated downloads, and increases reliability by insulating the pipeline from outages or rate limits of public registries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Caching dependencies from public repositories to improve build speed and reliability.

    Why this is correct

    CodeArtifact acts as an intermediary upstream repository, caching packages from public registries such as npmjs, Maven Central, or PyPI. When CodeBuild first requests a dependency, CodeArtifact fetches it from the public source and stores a copy in your domain; subsequent builds retrieve the cached copy directly from CodeArtifact. This reduces external network round trips, minimizes build-time latency, and protects against upstream outages or sudden changes in public repositories.

  • ✗

    Storing Docker images that are used by ECS tasks.

    Why it's wrong here

    CodeArtifact is designed for software package managers like npm, Maven, PyPI, and NuGet—it stores versioned package artifacts and metadata, not container images. Docker images use the OCI image format and are stored in Amazon Elastic Container Registry (ECR), which integrates directly with ECS and EKS for pulling images at runtime. Although CodeArtifact could store a generic zip file, it lacks the image digests, layers, and registry compatibility that ECS tasks require for pulling Docker images.

  • ✓

    Hosting npm packages that are consumed by CodeBuild during the build phase.

    Why this is correct

    CodeArtifact can host private npm packages, and CodeBuild can be configured to use CodeArtifact as its npm registry during the build phase via the `aws codeartifact login` command or by setting `registry` in `.npmrc`. This allows build pipelines to consume internal, scoped npm packages that may not be publicly available, while also centralizing dependency management and versioning. Since CodeArtifact integrates natively with CodeBuild's execution environments, authentication is handled through IAM and AWS credentials rather than storing tokens in the build repository.

  • ✗

    Storing source code archives for use in deployment stages.

    Why it's wrong here

    CodeArtifact is for package artifacts generated from source code, not for storing the source code itself. Source code archives belong in CodeCommit (Git repos) or Amazon S3, where AWS CodePipeline and CodeDeploy reference them for build and deployment stages. Storing source archives in CodeArtifact would not preserve Git history, would lack VCS features like branching and merging, and would force deployment tooling to use package manager APIs instead of established source retrieval mechanisms.

  • ✗

    Hosting static website assets for deployment to S3.

    Why it's wrong here

    Static website assets such as HTML, CSS, JavaScript, and images are not software package artifacts and are best stored directly in Amazon S3, which supports static website hosting via configured bucket policies and custom domain mapping. CodeArtifact is intended for dependency packages consumed by package managers—it does not serve HTTP content, manage public access for browsers, or provide S3's integration with CloudFront and Route 53. Using CodeArtifact for static assets would require clients to authenticate as a package manager, making it unsuitable for public website delivery.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.