SOA-C02 Security and Compliance Practice Question
A company is using AWS CodePipeline to deploy a web application. The security team requires that all code changes be reviewed and approved before deployment to production. Which action should be taken to enforce this requirement?
⚠ Common exam trap
Test-takers frequently confuse source-level controls (like pull request requirements or IAM policies) with pipeline-level approval gates, mistakenly thinking that preventing direct pushes or requiring pull requests alone satisfies the deployment approval requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a manual approval action in the CodePipeline pipeline before the production deployment stage.
Adding a manual approval action in the CodePipeline pipeline before the production deployment stage enforces a required review and approval gate. This action pauses the pipeline at that point, waiting for an authorized user to manually approve the change before it proceeds to the production stage, directly meeting the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a manual approval action in the CodePipeline pipeline before the production deployment stage.
Why this is correct
A manual approval action is the only option that inserts a human decision gate directly into the CodePipeline execution. You configure an approval action by adding a stage of type 'Approval' with an SNS topic; the pipeline pauses once that stage is reached and sends a notification to the approver(s). The approver must have IAM permissions for codepipeline:PutApprovalResult to approve or reject, and the pipeline does not proceed to the production deployment stage until that explicit approval is granted. This enforces separation of duties and prevents unverified code from reaching production.
- ✗
Create an IAM policy that denies the codecommit:PutFile action unless the user is in a specific group.
Why it's wrong here
Denying the codecommit:PutFile action via IAM restricts who can commit directly to a CodeCommit repository, but it has no effect on the IAM role that CodePipeline uses to deploy. CodePipeline's execution is governed by its own service role (e.g., permissions for codecommit:GetCommit and codedeploy:CreateDeployment), not by the user's ability to push commits. A developer who triggers the pipeline still allows CodePipeline to pull the latest commit and deploy to production without any manual checkpoint. This control addresses source-code write access, not deployment authorization, so it fails to gate the production release.
- ✗
Enable AWS CloudTrail and create a CloudWatch Events rule to notify the security team of any deployments.
Why it's wrong here
Enabling CloudTrail and a CloudWatch Events rule is a detective control, not a preventive one. CloudTrail records API activity calls such as CreateDeployment or StartPipelineExecution, and the CloudWatch Events rule can trigger an SNS notification to the security team after the fact. However, these mechanisms do not pause or block the pipeline; the deployment proceeds regardless of whether any human reviews it. Notifications help with auditing and incident response after an unauthorized deployment, but they cannot enforce approval or prevent a deployment from reaching production.
- ✗
Configure a CodeCommit repository to require pull requests for all changes.
Why it's wrong here
Requiring pull requests for all CodeCommit changes enforces code review before a commit is merged, but it does not create a review gate in the deployment pipeline itself. Once a pull request is merged into the tracked branch, CodePipeline automatically picks up the new revision and continues through its stages immediately. Unless a separate manual approval action exists in the pipeline, there is no point where a human can veto the production deployment. Pull request approval is about code review before the source revision exists, not about approving the release to production after the code has been merged.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.