SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS CodePipeline to deploy a web application. The pipeline has a source stage (Amazon S3) and a deploy stage (AWS Elastic Beanstalk). The SysOps administrator needs to add a manual approval step before the deployment proceeds to the production environment. Which action should the administrator take?
⚠ Common exam trap
It's easy for candidates to confuse notification mechanisms (like SNS) with the actual approval action, or assume that external tools like CloudFormation change sets can serve as manual approval gates within a pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a manual approval action in the pipeline using the AWS CodePipeline approval action type.
AWS CodePipeline natively supports a manual approval action type that can be added as a stage in the pipeline. This action pauses the pipeline execution until an authorized user manually approves or rejects the deployment, allowing the SysOps administrator to gate the deployment to the production environment without external services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an approval stage in the pipeline using the Amazon SNS topic as a notification method.
Why it's wrong here
An Amazon SNS topic is only a notification channel; it cannot pause a pipeline or serve as an approval gate by itself. In CodePipeline, manual approval requires an action with the category "Approval" added to a stage, and while you may associate an SNS topic with that approval action to alert reviewers, simply adding the SNS topic as a stage does not stop the pipeline or enforce a review. Without the actual Approval action, the pipeline will continue executing past the stage, so this approach fails to meet the requirement.
- ✓
Add a manual approval action in the pipeline using the AWS CodePipeline approval action type.
Why this is correct
CodePipeline has a native manual approval action with the category "Approval" that can be inserted into any stage. When configured, this action pauses the pipeline and waits for an authorized user to approve or reject the deployment via the console, CLI, or PutApprovalResult API call. You can optionally attach an SNS topic to send notifications to approvers, but the verification step is enforced by the Approval action itself, making this the correct way to implement a manual gate within the existing pipeline.
- ✗
Use an AWS CloudFormation change set to require manual approval.
Why it's wrong here
An AWS CloudFormation change set lets you review stack changes before execution, but it is not a CodePipeline approval step and does not pause the pipeline automatically. In a CodePipeline deployment, you would still need a separate Approval action before executing a change set; the change set itself merely describes the proposed resources and requires a separate CloudFormation action to execute it. Using change sets alone would require manual intervention outside the pipeline's execution and does not integrate as a built-in approval gate.
- ✗
Create a separate pipeline for production and trigger it manually.
Why it's wrong here
Creating a second pipeline for production and triggering it manually avoids adding an approval step to the existing pipeline, but it duplicates the entire pipeline configuration and requires manual operation outside of CodePipeline's automated flow. This approach adds operational overhead, increases the risk of configuration drift between pipelines, and does not provide an inline manual approval checkpoint within a single pipeline. The requirement asks for a manual approval step in the pipeline, so this is less efficient and not the correct solution.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.