Write CDK assertions tests and set the CodeBuild build phase OnFailure property to ABORT
A company uses the AWS Cloud Development Kit (AWS CDK) to define its application. The company uses a pipeline that consists of AWS CodePipeline and AWS CodeBuild to deploy the CDK application. The company wants to introduce unit tests to the pipeline to test various infrastructure components. The company wants to ensure that a deployment proceeds if no unit tests result in a failure. Which combination of steps will enforce the testing requirement in the pipeline? (Choose two.)
Community Votes
100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Both halves are required: the tests must be written with the CDK assertions module using template.hasResourceProperties to assert expected resource properties, which is the mechanism for unit-testing infrastructure components (D), and the CodeBuild build phase must be configured with OnFailure set to ABORT so a test failure stops the pipeline before deployment proceeds (A). Option E's cdk diff checks whether any resources changed, which is a drift comparison rather than a test of expected properties, and it would fail whenever a legitimate change is made. Options B and C add cdk deploy flags that govern rollback and approval behavior rather than test gating.
The requirement is that unit tests run in the pipeline and that deployment proceeds only if no test fails. Writing tests with the AWS CDK assertions module and using the template.hasResourceProperties assertion verifies that synthesized infrastructure components have the expected properties, which is how infrastructure unit tests are expressed in CDK. On the pipeline side, setting the build phase OnFailure property to ABORT means a failed test run terminates the execution instead of continuing, so a failing test blocks the deployment.
Adding the --rollback true flag to the cdk deploy command (B) — that flag controls whether a failed deployment is rolled back, not whether a failing unit test blocks the deployment, so tests could fail and the deployment would still proceed. Adding the --require-approval any-change flag (C) — that governs deployment approvals, so while it introduces a manual gate it does not express the requirement that deployment proceeds only when no test fails, and it adds friction without being a test gate. Using the cdk diff command and failing if any resources have changed (E) — this compares the synthesized template against what is deployed, so it is a change detection mechanism rather than a unit test; it would fail on every intentional deployment and pass when a template's properties are wrong but unchanged.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that unit tests cover infrastructure components and that a deployment proceeds only if no test fails, which needs both a testing mechanism and a pipeline gate. For the tests, the AWS CDK assertions module is the supported way to unit-test synthesized infrastructure, and the template.hasResourceProperties assertion verifies that particular resources carry the expected property values, which is exactly what testing various infrastructure components means (D). For the gate, the CodeBuild build phase commands are updated to run the tests before deploying, and setting the OnFailure phase property to ABORT makes a failed build terminate the execution rather than continue, so a failing test blocks the deployment (A). Together the assertions module provides the tests and the ABORT setting enforces that deployment is conditional on them passing. A and D are the correct combination.Why the Other Options Are Wrong
B updates the build phase commands to run the tests and then deploy and adds the --rollback true flag to the cdk deploy command. The rollback flag determines whether a failed deployment is reverted; it has no bearing on whether a failing test blocks the deployment, so a test failure would still allow the deployment to proceed. C adds the --require-approval any-change flag to cdk deploy. This introduces a manual approval gate on changes, which is a different control from a test gate, and it does not express the requirement that deployment proceed only when no test fails. E creates a test using the cdk diff command and configures it to fail if any resources have changed. The diff command compares the synthesized template against the deployed resources, which is change detection rather than unit testing; it would fail on every legitimate deployment that changes anything and would pass even when the template contains incorrect properties, as long as nothing was deployed. A and D are correct.Community Comment Notes
Community voted A,D unanimously. jamesf explained that the OnFailure phase property set to ABORT ensures that if any test fails the pipeline stops, preventing deployment, which is the decisive behaviour. TEC1 described A as the crucial step that integrates the unit tests into the build phase and halts the pipeline on failure. trungtd, while noting some uncertainty, also selected A and D. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →