DOP-C02 SDLC Automation Practice Question
Which TWO best practices should be followed when configuring AWS CodeBuild projects to improve build performance and security? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse 'improving performance' with 'simplifying configuration' and choose options like using the 'latest' tag or granting broad permissions, overlooking the security and determinism trade-offs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the build project to use a custom VPC to access resources like private Amazon RDS databases
Configuring a CodeBuild project to use a custom VPC allows it to access resources that are not publicly accessible, such as private Amazon RDS databases or internal services, which is essential for building applications that depend on those resources. This also enhances security by keeping traffic within the VPC and avoiding exposure to the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run builds as the root user to avoid permission errors
Why it's wrong here
Running builds as the root user is a security anti-pattern: it grants the build process full control over the container, meaning any compromised dependency or injected command could lead to host-level privilege escalation or unauthorized access to build secrets. The correct approach is to use a non-root user (e.g., via the image's USER directive or the CodeBuild run-as parameter) so that permission errors are avoided by explicitly owning the necessary files and directories, not by running with elevated privileges. This aligns with the principle of least privilege and ensures the build environment is restricted to only what is required.
- ✗
Use the AWS managed policy 'AdministratorAccess' for the CodeBuild service role to avoid permission issues
Why it's wrong here
Attaching the AWS managed policy 'AdministratorAccess' to the CodeBuild service role is a serious violation of least privilege. This policy grants the role unrestricted access to all AWS services and actions, so if the build environment is compromised (e.g., via malicious dependencies or buildspec injection), an attacker could delete S3 buckets, modify IAM roles, or terminate EC2 instances. CodeBuild roles should be scoped narrowly to just the actions the build actually needs, such as s3:GetObject, s3:PutObject, logs:CreateLogStream, and ecr:GetAuthorizationToken, using customer-managed policies with explicit resource ARNs.
- ✓
Configure the build project to use a custom VPC to access resources like private Amazon RDS databases
Why this is correct
Configuring the build project to use a custom VPC is a best practice because it allows CodeBuild to securely access resources that are not publicly reachable, such as private Amazon RDS databases, internal load balancers, or AWS services via VPC endpoints. Without a VPC configuration, CodeBuild runs in AWS-managed compute and cannot resolve or connect to private IP addresses, forcing you to either expose those resources to the internet or use a NAT gateway with complex routing. By placing the build into a private subnet with proper security group rules, you can control both inbound and outbound traffic, ensuring the build only communicates with approved internal services and does not depend on the public internet.
- ✗
Always use the 'latest' tag for the build environment image to ensure up-to-date software
Why it's wrong here
Always using the 'latest' tag for the build environment image is an anti-pattern because container image tags are mutable and 'latest' points to whatever image was most recently pushed, which can introduce breaking changes, deprecated packages, or unpatched security vulnerabilities. This makes builds non-reproducible: the same commit can produce different behavior over time simply because the underlying image changed. Instead, you should pin the build image to a specific immutable tag (e.g., a version number like 4.0.1) or a digest (SHA256) so that every build uses the same software, enabling consistent testing, auditing, and vulnerability management.
- ✓
Enable Amazon S3 cache to store dependencies and reuse them across builds
Why this is correct
Enabling Amazon S3 cache for the build project is a best practice because it stores dependencies and intermediate artifacts in an S3 bucket, allowing subsequent builds to reuse them instead of re-downloading or recompiling from scratch. This not only reduces build time and cost but also decreases the attack surface by minimizing external fetches from public package registries. To use an S3 cache, you configure a cache bucket and prefix, and CodeBuild automatically saves and restores the cache after successful builds; unlike a local cache, S3 caching is durable and shared across concurrent, identical builds, making it ideal for CI/CD pipelines that run frequently.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.