Skip to content
BytePatterns

DOP-C02 · Domain 1: SDLC Automation · 22% of the exam

Task 1.3: Build and manage artifacts.

Producing and keeping what the pipeline ships: packages in CodeArtifact, objects in S3 and images in ECR, who may read them, how long they live, and AMIs and container images built by EC2 Image Builder.

Study it

  • Artifacts: CodeArtifact, S3 and Amazon ECR, with access and lifecycle

    Partly covered by: Images, Layers & Multi-Stage Builds

  • Golden images: EC2 Image Builder pipelines for AMIs and container images

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company has 40 development accounts in AWS Organizations. Builds in AWS CodeBuild must install npm packages only through a company-controlled repository so that the security team can block packages centrally later. A public package fetched once must be reused by every team instead of being fetched from npmjs.com again. Which design meets these requirements with the least operational overhead?

  1. ACreate an Amazon ECR pull through cache rule for the npm public registry in a shared account and grant the organization access through the private registry's permissions policy
  2. BCreate a CodeArtifact repository with an external connection to npmjs.com in each development account and point builds at it
  3. CCreate a shared CodeArtifact domain with one repository that connects externally to npmjs.com, team repositories that use it as an upstream, and a domain policy for the organization
  4. DMirror the npm packages the teams use into an S3 bucket every night with a scheduled CodeBuild job and point npm at the bucket
Show the answer and why
  • ACreate an Amazon ECR pull through cache rule for the npm public registry in a shared account and grant the organization access through the private registry's permissions policy

    Incorrect

    Pull through cache rules sync upstream container image registries into a private registry. npm is not a supported upstream.

  • BCreate a CodeArtifact repository with an external connection to npmjs.com in each development account and point builds at it

    Incorrect

    Each account would fetch and store the same public packages again. The intended pattern is one repository per domain with the external connection and other repositories using it as an upstream.

  • CCreate a shared CodeArtifact domain with one repository that connects externally to npmjs.com, team repositories that use it as an upstream, and a domain policy for the organization

    Correct

    Packages fetched once through the external connection are reused by all downstream repositories, and a domain policy can grant principals in other accounts access to the domain.

  • DMirror the npm packages the teams use into an S3 bucket every night with a scheduled CodeBuild job and point npm at the bucket

    Incorrect

    This is custom tooling to build and run, and packages first requested during the day are missing until the next run. CodeArtifact fetches a missing package on request.

CodeArtifact keeps packages from a public repository after the first fetch through an external connection. Putting that connection on one repository in a shared domain, with team repositories as downstreams and cross-account access through the domain policy, gives one control point for all accounts.

Question 2 · choose 2

Amazon ECS task definitions in production reference images in an Amazon ECR repository by tags such as release-2026.10.3. An incident happened when a CI job pushed a different image under an existing release tag. The repository also holds thousands of untagged images from branch builds. Release tags must never point to a different image, untagged images older than 14 days must be removed automatically, and the 100 most recent release images must always be kept. Which actions meet these requirements? (Choose TWO.)

  1. ATurn on scan on push for the repository so that an image pushed under an existing tag is rejected
  2. BSet image tag mutability on the repository to immutable
  3. CKeep the repository mutable and add a CI check that fails a build when its tag already exists in the repository
  4. DConfigure cross-Region replication so that a copy of every release image is kept in a second Region
  5. EAdd a lifecycle policy that expires untagged images 14 days after push and expires release images beyond the newest 100 by tag prefix
Show the answer and why
  • ATurn on scan on push for the repository so that an image pushed under an existing tag is rejected

    Incorrect

    Image scanning looks for software vulnerabilities in images. It does not reject a push or protect tags.

  • BSet image tag mutability on the repository to immutable

    Correct

    With tag immutability turned on, a push that would overwrite an existing tag in the repository is refused.

  • CKeep the repository mutable and add a CI check that fails a build when its tag already exists in the repository

    Incorrect

    A check in one pipeline does not protect the repository: anyone else with push permission could still overwrite a tag while it is mutable.

  • DConfigure cross-Region replication so that a copy of every release image is kept in a second Region

    Incorrect

    Replication copies images to another Region or account. It neither protects tags nor removes old untagged images.

  • EAdd a lifecycle policy that expires untagged images 14 days after push and expires release images beyond the newest 100 by tag prefix

    Correct

    Lifecycle rules can select untagged images with sinceImagePushed and images with a tag prefix with imageCountMoreThan, removing older images first.

Tag immutability protects what a tag points to, and lifecycle policies clean up by age or count. Combining both keeps the release tags trustworthy while the storage of build leftovers stops growing.

Question 3 · choose 1

A company must give 30 workload accounts in two AWS Regions a hardened Amazon Linux AMI. A new AMI must be built only when the base image or one of the hardening components has changed, it must pass the company's tests before any account can use it, and the solution must need as little custom code as possible. Which solution meets these requirements?

  1. AAn EC2 Image Builder pipeline with build and test components, a monthly cron schedule that always runs, and a distribution configuration for both Regions and the workload accounts
  2. BAn EC2 Image Builder pipeline with build and test components, a cron schedule that runs only when dependency updates are available, and distribution to both Regions and the workload accounts
  3. CAn EC2 Image Builder pipeline with build and test components, a cron schedule that runs only when dependency updates are available, and distribution to the workload accounts in the Region where it is built
  4. DA Systems Manager Automation runbook that patches an instance and creates an AMI, plus a Lambda function that copies and shares it, both started monthly by EventBridge Scheduler
Show the answer and why
  • AAn EC2 Image Builder pipeline with build and test components, a monthly cron schedule that always runs, and a distribution configuration for both Regions and the workload accounts

    Incorrect

    A schedule that always runs builds an image even when nothing changed. Image Builder can skip a scheduled run unless there are dependency updates.

  • BAn EC2 Image Builder pipeline with build and test components, a cron schedule that runs only when dependency updates are available, and distribution to both Regions and the workload accounts

    Correct

    Image Builder skips scheduled runs without changes to the base image or components, distributes an image only if all its tests pass, and delivers it to the Regions and accounts in the distribution settings.

  • CAn EC2 Image Builder pipeline with build and test components, a cron schedule that runs only when dependency updates are available, and distribution to the workload accounts in the Region where it is built

    Incorrect

    Distribution settings list each Region to deliver to, so accounts in the second Region would get no copy of the AMI.

  • DA Systems Manager Automation runbook that patches an instance and creates an AMI, plus a Lambda function that copies and shares it, both started monthly by EventBridge Scheduler

    Incorrect

    This needs custom code for copying, sharing and testing, and it builds every month whether or not anything changed. Image Builder provides all of it.

EC2 Image Builder covers the whole AMI life cycle: build and test components, a schedule that can wait for dependency updates, and distribution to several Regions and accounts. Three options here are Image Builder pipelines that differ in one setting; only one meets every requirement.

Question 4 · choose 1

An ECR registry uses pull through cache rules for public images and replication to a second Region. Repositories that ECR creates for these features get default settings: mutable tags, AES-256 encryption and no lifecycle policy. Security wants every such repository created with tag immutability, a customer managed KMS key and a lifecycle policy. What should the DevOps engineer do?

  1. ARun a nightly Lambda function that updates the settings of every repository created during the day
  2. BDeploy AWS Config rules for ECR repository settings with automatic remediation through Systems Manager Automation
  3. CCreate repository creation templates for the pull through cache and replication prefixes
  4. DCreate every repository in advance with the required settings so that ECR never creates one
Show the answer and why
  • ARun a nightly Lambda function that updates the settings of every repository created during the day

    Incorrect

    This fixes repositories after they are created and adds custom code, and a repository's encryption configuration cannot be changed after creation.

  • BDeploy AWS Config rules for ECR repository settings with automatic remediation through Systems Manager Automation

    Incorrect

    Remediation acts only after a repository exists and is evaluated, and it cannot switch an existing repository to a KMS key because the encryption configuration is fixed at creation.

  • CCreate repository creation templates for the pull through cache and replication prefixes

    Correct

    Templates define the settings of repositories that ECR creates for pull through cache, create on push and replication.

  • DCreate every repository in advance with the required settings so that ECR never creates one

    Incorrect

    Upstream images and replicated repositories change over time, so repositories cannot all be known in advance.

Repository creation templates apply only when ECR creates a repository on your behalf. Without a matching template, ECR uses default settings such as mutable tags and AES-256 encryption.

Question 5 · choose 3

CodeBuild projects run in private subnets that have no route to the internet. Maven builds must download packages from a CodeArtifact repository in the same Region. Which VPC endpoints must the DevOps engineer create? (Choose THREE.)

  1. AAn interface endpoint for com.amazonaws.region.codeartifact.api
  2. BA gateway endpoint for CodeArtifact in the route tables of the private subnets
  3. CAn interface endpoint for com.amazonaws.region.codeartifact.repositories with private DNS turned on
  4. DA gateway endpoint for Amazon S3 in the route tables of the private subnets
  5. EAn interface endpoint for AWS CodeBuild so that the build can reach the repository
Show the answer and why
  • AAn interface endpoint for com.amazonaws.region.codeartifact.api

    Correct

    This endpoint is used to call CodeArtifact APIs, such as getting an authorization token.

  • BA gateway endpoint for CodeArtifact in the route tables of the private subnets

    Incorrect

    CodeArtifact is reached through interface endpoints; gateway endpoints are for Amazon S3 and DynamoDB.

  • CAn interface endpoint for com.amazonaws.region.codeartifact.repositories with private DNS turned on

    Correct

    Package managers use this endpoint to reach repositories, and it needs a private DNS hostname or extra configuration.

  • DA gateway endpoint for Amazon S3 in the route tables of the private subnets

    Correct

    CodeArtifact stores package assets in S3, so Maven downloads need an S3 gateway endpoint.

  • EAn interface endpoint for AWS CodeBuild so that the build can reach the repository

    Incorrect

    A CodeBuild endpoint is for calling CodeBuild APIs, not for downloading packages.

From a VPC without internet access, CodeArtifact needs its api and repositories interface endpoints, plus an S3 gateway endpoint for package assets in most formats.

Question 6 · choose 1

Regulators require that every release artifact in an S3 bucket cannot be overwritten or deleted by any user, including the root user, for five years after it is stored. After that, the artifacts must become deletable on their own so that an S3 Lifecycle rule can remove them, without anyone releasing objects one by one. The pipeline keeps uploading new builds under existing keys. What should the DevOps engineer configure on the bucket?

  1. AS3 Object Lock in compliance mode with a default retention period of five years
  2. BS3 Object Lock in governance mode with a default retention period of five years
  3. CAn S3 Object Lock legal hold that the pipeline places on each artifact when it uploads it
  4. DS3 Versioning with MFA delete, turned on by the root user of the account that owns the bucket
Show the answer and why
  • AS3 Object Lock in compliance mode with a default retention period of five years

    Correct

    No user, including the root user, can delete a locked version or shorten its retention, and each version becomes deletable when its retention period ends; new uploads become new versions.

  • BS3 Object Lock in governance mode with a default retention period of five years

    Incorrect

    Retention also ends on its own, but users with the s3:BypassGovernanceRetention permission can delete versions or change their retention early.

  • CAn S3 Object Lock legal hold that the pipeline places on each artifact when it uploads it

    Incorrect

    A legal hold suits an unknown duration, but it never expires on its own, and any user with s3:PutObjectLegalHold can remove it.

  • DS3 Versioning with MFA delete, turned on by the root user of the account that owns the bucket

    Incorrect

    The bucket owner can still delete versions with an MFA code, and MFA delete cannot be used with lifecycle configurations.

Compliance-mode retention is the only option that binds every user, including the root user, for a fixed period and then lifts by itself. Object Lock requires versioning, so an upload under an existing key adds a new version and leaves the locked one in place.

Question 7 · choose 1

A platform team publishes a Lambda layer with shared observability code in its tools account. Functions in all accounts of the company's organization must be able to use specific layer versions, and accounts that join later must get access automatically. What should the DevOps engineer do?

  1. ACopy the layer into every account with a StackSet each time a new version is published
  2. BAdd a layer version permission that grants lambda:GetLayerVersion to the organization
  3. CShare the layer through AWS RAM with the organization's root OU
  4. DMake the layer public with a grant to all accounts so that the organization can use it
Show the answer and why
  • ACopy the layer into every account with a StackSet each time a new version is published

    Incorrect

    This creates copies to maintain instead of sharing one layer version.

  • BAdd a layer version permission that grants lambda:GetLayerVersion to the organization

    Correct

    Layer version permissions can grant access to a single account, all accounts, or an organization.

  • CShare the layer through AWS RAM with the organization's root OU

    Incorrect

    Layer access is granted with the layer's resource-based policy.

  • DMake the layer public with a grant to all accounts so that the organization can use it

    Incorrect

    This opens the layer to every AWS account, not only the organization.

Lambda layers are shared with a resource-based permission on each layer version. A statement can name one account, all accounts or an organization in AWS Organizations.

Question 8 · choose 1

An Image Builder pipeline in a tools account builds a hardened AMI that is encrypted with a customer managed KMS key. Five workload accounts must be able to launch instances from each new AMI automatically after a build. What should the DevOps engineer configure?

  1. AImage Builder distribution settings for the workload accounts, with KMS key access for them
  2. BA daily script in each workload account that copies the newest AMI from the tools account
  3. CAn S3 bucket policy that lets the workload accounts read the AMI's snapshots directly
  4. DAn advanced Parameter Store parameter with the latest AMI ID, shared with the workload accounts through AWS RAM
Show the answer and why
  • AImage Builder distribution settings for the workload accounts, with KMS key access for them

    Correct

    Image Builder distribution can deliver AMIs to other accounts, and encrypted AMIs need key access in the target accounts.

  • BA daily script in each workload account that copies the newest AMI from the tools account

    Incorrect

    This adds a script in every account for work that distribution settings do.

  • CAn S3 bucket policy that lets the workload accounts read the AMI's snapshots directly

    Incorrect

    AMIs are shared through launch permissions or distribution, not through a bucket policy.

  • DAn advanced Parameter Store parameter with the latest AMI ID, shared with the workload accounts through AWS RAM

    Incorrect

    Shared parameters give other accounts read-only access to the AMI ID, but not permission to launch the AMI or to use its KMS key.

Image Builder distribution settings can deliver output AMIs to other accounts as part of each build. For AMIs encrypted with a customer managed key, the key policy must allow the target accounts.

Practise domain 1 →Practise all domains →