Courseiva
SDLC Automation →mediumMultiple Select

DOP-C02 SDLC Automation Practice Question

Which TWO best practices should be followed when configuring AWS CodeBuild projects to improve build performance and security? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse 'improving performance' with 'simplifying configuration' and choose options like using the 'latest' tag or granting broad permissions, overlooking the security and determinism trade-offs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the build project to use a custom VPC to access resources like private Amazon RDS databases

Configuring a CodeBuild project to use a custom VPC allows it to access resources that are not publicly accessible, such as private Amazon RDS databases or internal services, which is essential for building applications that depend on those resources. This also enhances security by keeping traffic within the VPC and avoiding exposure to the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run builds as the root user to avoid permission errors

    Why it's wrong here

    Running builds as the root user is a security anti-pattern: it grants the build process full control over the container, meaning any compromised dependency or injected command could lead to host-level privilege escalation or unauthorized access to build secrets. The correct approach is to use a non-root user (e.g., via the image's USER directive or the CodeBuild run-as parameter) so that permission errors are avoided by explicitly owning the necessary files and directories, not by running with elevated privileges. This aligns with the principle of least privilege and ensures the build environment is restricted to only what is required.

  • ✗

    Use the AWS managed policy 'AdministratorAccess' for the CodeBuild service role to avoid permission issues

    Why it's wrong here

    Attaching the AWS managed policy 'AdministratorAccess' to the CodeBuild service role is a serious violation of least privilege. This policy grants the role unrestricted access to all AWS services and actions, so if the build environment is compromised (e.g., via malicious dependencies or buildspec injection), an attacker could delete S3 buckets, modify IAM roles, or terminate EC2 instances. CodeBuild roles should be scoped narrowly to just the actions the build actually needs, such as s3:GetObject, s3:PutObject, logs:CreateLogStream, and ecr:GetAuthorizationToken, using customer-managed policies with explicit resource ARNs.

  • ✓

    Configure the build project to use a custom VPC to access resources like private Amazon RDS databases

    Why this is correct

    Configuring the build project to use a custom VPC is a best practice because it allows CodeBuild to securely access resources that are not publicly reachable, such as private Amazon RDS databases, internal load balancers, or AWS services via VPC endpoints. Without a VPC configuration, CodeBuild runs in AWS-managed compute and cannot resolve or connect to private IP addresses, forcing you to either expose those resources to the internet or use a NAT gateway with complex routing. By placing the build into a private subnet with proper security group rules, you can control both inbound and outbound traffic, ensuring the build only communicates with approved internal services and does not depend on the public internet.

  • ✗

    Always use the 'latest' tag for the build environment image to ensure up-to-date software

    Why it's wrong here

    Always using the 'latest' tag for the build environment image is an anti-pattern because container image tags are mutable and 'latest' points to whatever image was most recently pushed, which can introduce breaking changes, deprecated packages, or unpatched security vulnerabilities. This makes builds non-reproducible: the same commit can produce different behavior over time simply because the underlying image changed. Instead, you should pin the build image to a specific immutable tag (e.g., a version number like 4.0.1) or a digest (SHA256) so that every build uses the same software, enabling consistent testing, auditing, and vulnerability management.

  • ✓

    Enable Amazon S3 cache to store dependencies and reuse them across builds

    Why this is correct

    Enabling Amazon S3 cache for the build project is a best practice because it stores dependencies and intermediate artifacts in an S3 bucket, allowing subsequent builds to reuse them instead of re-downloading or recompiling from scratch. This not only reduces build time and cost but also decreases the attack surface by minimizing external fetches from public package registries. To use an S3 cache, you configure a cache bucket and prefix, and CodeBuild automatically saves and restores the cache after successful builds; unlike a local cache, S3 caching is durable and shared across concurrent, identical builds, making it ideal for CI/CD pipelines that run frequently.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.