SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS CodePipeline with AWS CodeBuild to build and deploy a static website to an S3 bucket. The website is served via Amazon CloudFront. The deployment fails intermittently because the S3 bucket policy does not allow CloudFront access after the bucket is updated. What is the BEST way to automate the bucket policy update during the deployment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation to manage the S3 bucket and its policy, and update the stack as part of the pipeline.
AWS CloudFormation can manage the S3 bucket and its policy as part of the infrastructure. Using CloudFormation, the bucket policy can be updated automatically when the stack is updated, ensuring that CloudFront access is maintained. Option A is incorrect because including an AWS CLI command in the buildspec may work but is less robust and not as automated as using CloudFormation. Option C is incorrect because manually adding a bucket policy statement in the S3 management console is not automated and prone to errors. Option D is incorrect because while using a CloudFront origin access identity (OAI) and configuring it in the bucket policy is a best practice, it does not automate the policy update during deployment; CloudFormation handles this automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include an AWS CLI command in the buildspec to update the bucket policy after the build.
Why it's wrong here
Running an AWS CLI command in the buildspec to modify the bucket policy is an imperative, ad-hoc approach. It requires the CodeBuild role to have s3:PutBucketPolicy permissions, is not idempotent, and can silently fail or overwrite changes if the policy document is not correctly parsed. It also bypasses version control and formal change management, making rollback and auditing difficult. CloudFormation instead declaratively manages the policy, enforcing consistency and automated rollback.
- ✓
Use AWS CloudFormation to manage the S3 bucket and its policy, and update the stack as part of the pipeline.
Why this is correct
Using CloudFormation to manage the S3 bucket and its bucket policy is the recommended infrastructure-as-code practice. When the stack is updated as part of the CodePipeline execution, any policy changes are applied deterministically, with drift detection and automatic rollback on failure. This ensures the CloudFront origin access configuration and bucket policy remain in sync across every deployment, eliminating manual intervention and reducing the risk of misconfiguration.
- ✗
Add a bucket policy statement in the S3 management console to grant CloudFront access.
Why it's wrong here
Manually adding a bucket policy statement in the S3 console is not automated and introduces human error. It requires someone to notice that the policy must change, then manually edit the JSON, which is error-prone and not repeatable across environments. This approach also lacks version control and rollback, so a mistyped principal or action could inadvertently lock out CloudFront or expose the bucket. In a CI/CD pipeline, such manual steps defeat the goal of fully automated, auditable deployments.
- ✗
Use a CloudFront origin access identity (OAI) and configure it in the bucket policy.
Why it's wrong here
Configuring a CloudFront OAI and referencing it in the bucket policy is a valid static configuration, but it does not automate the policy update as part of the pipeline. The question specifically asks about updating the bucket policy during deployment — simply creating an OAI does not cause the pipeline to modify the policy when needed. If requirements change (e.g., switching to an origin access control or altering allowed HTTP methods), the policy must still be updated via a separate manual or automated process. CloudFormation provides that automation by tying the policy lifecycle to stack updates.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.