exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 180 discussion

A company is using AWS CodePipeline to deploy an application. According to a new guideline, a member of the company's security team must sign off on any application changes before the changes are deployed into production. The approval must be recorded and retained.

Which combination of actions will meet these requirements? (Choose two.)

  • A. Configure CodePipeline to write actions to Amazon CloudWatch Logs.
  • B. Configure CodePipeline to write actions to an Amazon S3 bucket at the end of each pipeline stage.
  • C. Create an AWS CloudTrail trail to deliver logs to Amazon S3.
  • D. Create a CodePipeline custom action to invoke an AWS Lambda function for approval. Create a policy that gives the security team access to manage CodePipeline custom actions.
  • E. Create a CodePipeline manual approval action before the deployment step. Create a policy that grants the security team access to approve manual approval stages.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
thanhnv142
Highly Voted 8 months, 3 weeks ago
Selected Answer: CE
C and E are correct: A: Cloudwatch Logs is to store logs from AWS resources like EC2, not codepipeline B: We dont need to store codepipeline actions in S3. C: We need to monitor users'actions, so using cloudtrail to store logs to S3 is the recommended one D: We should not invoke AWS lambda for approval E: This is the recommended one
upvoted 6 times
...
youonebe
Most Recent 4 months, 1 week ago
Selected Answer: AE
CloudTrail tracks API activity in your AWS environment, but it does not specifically capture manual approval actions within CodePipeline. CloudTrail can help you audit changes to resources but is not suited for tracking the specific approval process within CodePipeline itself.
upvoted 2 times
...
c3518fc
6 months, 1 week ago
Selected Answer: CE
https://docs.aws.amazon.com/codepipeline/latest/userguide/monitoring-cloudtrail-logs.html
upvoted 3 times
...
dkp
6 months, 3 weeks ago
ans ce
upvoted 1 times
...
WhyIronMan
7 months, 1 week ago
Selected Answer: CE
C- Logging, since Cloudwatch Logs and writelogs to S3 can not capture the Approval that only CloudTrail can E - Manual Approval Step is natively supported by codepipeline, no need to make it more complex with anything
upvoted 3 times
...
DanShone
7 months, 3 weeks ago
Selected Answer: CE
C- Logging E - Manual Approval Step
upvoted 2 times
...
[Removed]
8 months, 1 week ago
Selected Answer: CE
C-E for sure
upvoted 2 times
...
davdan99
9 months, 4 weeks ago
Selected Answer: CE
https://stelligent.com/2019/06/11/aws-codepipeline-approval-gate-tracking/
upvoted 2 times
...
zolthar_z
10 months, 1 week ago
Selected Answer: CE
C and E: The approval process is an AWS API Event and this is managed by CloudTrail https://docs.aws.amazon.com/codepipeline/latest/userguide/incident-response.html
upvoted 3 times
...
ozansenturk
10 months, 1 week ago
Selected Answer: CE
CE: AWS CodePipeline is integrated with AWS CloudTrail, a service that provides a record of actions taken by a user, role, or an AWS service in CodePipeline;. CloudTrail captures all API calls for CodePipeline as events. The calls captured include calls from the CodePipeline console and code calls to the CodePipeline API operations. If you create a trail, you can enable continuous delivery of CloudTrail events to an Amazon S3 bucket, including events for CodePipeline. If you don't configure a trail, you can still view the most recent events in the CloudTrail console in Event history. Using the information collected by CloudTrail, you can determine the request that was made to CodePipeline, the IP address from which the request was made, who made the request, when it was made, and additional details. https://docs.aws.amazon.com/codepipeline/latest/userguide/monitoring-cloudtrail-logs.html
upvoted 2 times
...
d262e67
10 months, 1 week ago
Selected Answer: CE
C. because actions performed by the security team are api calls. And api calls go into CloudTrail, if you want to retain them we have to send them into an S3 bucket. https://docs.aws.amazon.com/codepipeline/latest/userguide/monitoring-cloudtrail-logs.html
upvoted 3 times
...
GokSK
10 months, 1 week ago
Selected Answer: AE
E is for Manual Approval A is for recorded and retained
upvoted 2 times
...
PrasannaBalaji
10 months, 1 week ago
Selected Answer: DE
D and E is correct
upvoted 1 times
WhyIronMan
7 months, 1 week ago
Option D does not address the need "The approval must be recorded and retained."
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago