Store guardrail templates in CodeCommit and auto-trigger a CodePipeline pipeline via EventBridge for each OU
A DevOps engineer deployed multiple AWS accounts by using AWS Control Tower to support different business, technical, and administrative units in a company. A security team needs the DevOps engineer to automate AWS Control Tower guardrails for the company. The guardrails must be applied to all accounts in an OU of the company's organization in AWS Organizations. The security team needs a solution that has version control and can be reviewed and rolled back if necessary. The security team will maintain the management of the solution in its OU. The security team wants to limit the type of guardrails that are allowed and allow only new guardrails that are approved by the security team. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The approval requirement is what makes the pipeline event-driven on repository changes rather than manually started. An EventBridge rule on the security team's CodeCommit changes means a guardrail only reaches the organization when it is committed to the reviewed repository, which is the approval gate, and the automation then removes the need to invoke the pipeline manually (C). Option A uses CodeBuild rather than CodePipeline, which lacks the staged review and rollback capability. Option B requires the team to invoke the pipeline and supply parameters each time, which is manual. Option D stores templates in S3 and triggers on PutObject, which loses the version control the requirement demands.
The guardrails must be version controlled, reviewable, and rollbackable, must be maintained by the security team in their own organizational unit, and only approved new guardrails may be applied. Storing individual CloudFormation templates containing an AWS::ControlTower::EnableControl resource in a CodeCommit repository provides the version control and review the security team needs, with the resource declared once per OU. A CodePipeline pipeline in the security team's account is then invoked by an Amazon EventBridge rule watching for changes to that CodeCommit repository, so an approved commit automatically flows through the pipeline and applies the guardrails, without anyone invoking the pipeline by hand.
Using a CodeBuild project invoked by EventBridge instead of a CodePipeline pipeline (A) — CodeBuild is a build service and does not provide the staged pipeline with source, approval, and deployment stages that the requirement's review and rollback needs depend on, so a commit could not be gated before it took effect. Instructing the security team to invoke the pipeline and provide parameters manually (B) — that requires a person to start each deployment, which loses the approval-by-commit property and adds a manual step on every guardrail change. Storing the templates in an Amazon S3 bucket and triggering on PutObject events (D) — as c87b433 noted, this removes the source-of-truth versioning that CodeCommit provides, so the requirement for version control, review, and rollback is not satisfied.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The solution must satisfy four properties: the guardrails are applied to all accounts in an organizational unit, they are under version control so they can be reviewed and rolled back, they are managed by the security team within their own OU, and only new guardrails the security team has approved may be applied. Storing individual CloudFormation templates, each containing an AWS::ControlTower::EnableControl logical resource for an organizational unit, in an AWS CodeCommit repository provides the version control, the review workflow through pull requests, and the rollback capability through commit history that the requirement asks for (C). A CodePipeline pipeline in the security team's account is then configured, and an Amazon EventBridge rule is set to invoke it when changes occur in that CodeCommit repository (C). Because the pipeline runs only in response to a repository change, a guardrail takes effect only after it has been committed, which makes the commit the approval gate and satisfies the requirement that only approved guardrails be applied; it also removes the manual pipeline invocation step. Srikantha noted that version control is managed through CodeCommit so guardrail changes can be reviewed and rolled back if necessary, and that approval and governance are built into the process. uncledana described C as the most efficient and scalable solution, meeting the requirements for version control, approval, and rollback with minimal effort. C is the correct answer.Why the Other Options Are Wrong
A creates individual CloudFormation templates containing the EnableControl resource and stores them in CodeCommit, but configures an AWS CodeBuild project that an EventBridge rule invokes on CodeCommit changes, and declares the resource for each OU. Using CodeBuild rather than CodePipeline is the defect: CodeBuild performs a build and cannot provide the staged source, approval, and deploy phases that the requirement's review, approval, and rollback behavior depends on, so a commit would not be gated before its changes took effect. B creates the same CodeCommit-stored templates but configures a CodePipeline pipeline that the security team invokes manually, supplying parameters at each start. Requiring a person to start every deployment means a guardrail could not be applied through an approved commit alone and adds a manual step for every change, which weakens the approval property and increases operational effort. D configures a CodePipeline pipeline invoked by an EventBridge rule on PutObject events to an S3 bucket, and stores the templates in that bucket. As c87b433 pointed out, storing the source templates in S3 rather than a version-controlled repository removes the version control, review, and rollback capability the requirement explicitly demands. C is correct.Community Comment Notes
Community voted C (83), with D a minority (17). Srikantha explained that version control is managed through CodeCommit so guardrail changes can be reviewed and rolled back if necessary, and that approval and governance are built into the process. uncledana described C as the most efficient and scalable option for automating guardrails while meeting the requirements for version control, approval, and rollback. c87b433 was the sole dissenter, noting that option D uses PutObject events to an S3 bucket to invoke CodePipeline whereas the solution should be invoked by the security team's commits, which is precisely the versioning objection. No alternative received majority support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →