Store guardrail templates in CodeCommit and auto-trigger a CodePipeline pipeline via EventBridge for each OU

Answer Correct answer: C — store guardrail templates in CodeCommit and let an EventBridge rule trigger CodePipeline for each OU.

A DevOps engineer deployed multiple AWS accounts by using AWS Control Tower to support different business, technical, and administrative units in a company. A security team needs the DevOps engineer to automate AWS Control Tower guardrails for the company. The guardrails must be applied to all accounts in an OU of the company's organization in AWS Organizations. The security team needs a solution that has version control and can be reviewed and rolled back if necessary. The security team will maintain the management of the solution in its OU. The security team wants to limit the type of guardrails that are allowed and allow only new guardrails that are approved by the security team. Which solution will meet these requirements with the MOST operational efficiency?

  1. Create individual AWS CloudFormation templates that align to a guardrail. Store the templates in an AWS CodeCommit repository. Create an AWS::ControlTower::EnableControl logical resource in the template for each OU in the organization. Configure an AWS Code Build project that an Amazon EventBridge rule will invoke for the security team's AWS CodeCommit changes.
  2. Create individual AWS CloudFormation templates that align to a guardrail. Store the templates in an AWS CodeCommit repository. Create an AWS::ControlTower::EnableControl logical resource in the template for each account in the organization. Configure an AWS CodePipeline pipeline in the security team's account. Advise the security team to invoke the pipeline and provide these parameters when starting the pipeline.
  3. Create individual AWS CloudFormation templates that align to a guardrail. Store the templates in an AWS CodeCommit repository. Create an AWS::ControlTower::EnableControl logical resource in the template for each OU in the organization. Configure an AWS CodePipeline pipeline in the security team's account that an Amazon EventBridge rule will invoke for the security team's CodeCommit changes. Correct Answer
  4. Configure an AWS CodePipeline pipeline in the security team's account that an Amazon EventBridge rule will invoke for PutObject events to an Amazon S3 bucket. Create individual AWS CloudFormation templates that align to a guardrail. Store the templates in the S3 bucket. Create an AWS::ControlTower::EnableControl logical resource in the template for each OU in the organization.

Community Votes

C
83%
D
17%

83% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The approval requirement is what makes the pipeline event-driven on repository changes rather than manually started. An EventBridge rule on the security team's CodeCommit changes means a guardrail only reaches the organization when it is committed to the reviewed repository, which is the approval gate, and the automation then removes the need to invoke the pipeline manually (C). Option A uses CodeBuild rather than CodePipeline, which lacks the staged review and rollback capability. Option B requires the team to invoke the pipeline and supply parameters each time, which is manual. Option D stores templates in S3 and triggers on PutObject, which loses the version control the requirement demands.

The guardrails must be version controlled, reviewable, and rollbackable, must be maintained by the security team in their own organizational unit, and only approved new guardrails may be applied. Storing individual CloudFormation templates containing an AWS::ControlTower::EnableControl resource in a CodeCommit repository provides the version control and review the security team needs, with the resource declared once per OU. A CodePipeline pipeline in the security team's account is then invoked by an Amazon EventBridge rule watching for changes to that CodeCommit repository, so an approved commit automatically flows through the pipeline and applies the guardrails, without anyone invoking the pipeline by hand.

Using a CodeBuild project invoked by EventBridge instead of a CodePipeline pipeline (A) — CodeBuild is a build service and does not provide the staged pipeline with source, approval, and deployment stages that the requirement's review and rollback needs depend on, so a commit could not be gated before it took effect. Instructing the security team to invoke the pipeline and provide parameters manually (B) — that requires a person to start each deployment, which loses the approval-by-commit property and adds a manual step on every guardrail change. Storing the templates in an Amazon S3 bucket and triggering on PutObject events (D) — as c87b433 noted, this removes the source-of-truth versioning that CodeCommit provides, so the requirement for version control, review, and rollback is not satisfied.

Community Discussion (3 comments)

Srikantha 👍 1 Selected: C
Version control is managed easily with CodeCommit, and the changes to the guardrails can be reviewed and rolled back if necessary. Approval and governance are built into the process, with the security team controlling the changes and ensuring that only approved guardrails are applied. Automation through CodePipeline and EventBridge ensures that the guardrails are applied to the correct OUs automatically, without the need for manual processes or additional operational overhead. The solution is scalable as it can be applied to multiple OUs and accounts.
c87b433 👍 1 Selected: D
D is not right because solution should be like AWS CodePipeline pipeline must be invooked by security team commits. But in D, PutObject events to an Amazon S3 bucket is used to invoke CodePipeline. A is using AWS Code Build unnecesaarily on Amazon EventBridge rule. It does not say anything automated and involve manual efforts. B is completely manual steps mentioned in the line so can't be efficient. C is completely automated so its a right answer.
uncledana 👍 4 Selected: C
Option C is the most efficient and scalable solution for automating AWS Control Tower guardrails while meeting the security team’s requirements for version control, approval, and rollback, with minimal operational overhead. It uses CodeCommit, CodePipeline, and EventBridge, leveraging the best AWS services for this purpose.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The solution must satisfy four properties: the guardrails are applied to all accounts in an organizational unit, they are under version control so they can be reviewed and rolled back, they are managed by the security team within their own OU, and only new guardrails the security team has approved may be applied. Storing individual CloudFormation templates, each containing an AWS::ControlTower::EnableControl logical resource for an organizational unit, in an AWS CodeCommit repository provides the version control, the review workflow through pull requests, and the rollback capability through commit history that the requirement asks for (C). A CodePipeline pipeline in the security team's account is then configured, and an Amazon EventBridge rule is set to invoke it when changes occur in that CodeCommit repository (C). Because the pipeline runs only in response to a repository change, a guardrail takes effect only after it has been committed, which makes the commit the approval gate and satisfies the requirement that only approved guardrails be applied; it also removes the manual pipeline invocation step. Srikantha noted that version control is managed through CodeCommit so guardrail changes can be reviewed and rolled back if necessary, and that approval and governance are built into the process. uncledana described C as the most efficient and scalable solution, meeting the requirements for version control, approval, and rollback with minimal effort. C is the correct answer.

Why the Other Options Are Wrong

A creates individual CloudFormation templates containing the EnableControl resource and stores them in CodeCommit, but configures an AWS CodeBuild project that an EventBridge rule invokes on CodeCommit changes, and declares the resource for each OU. Using CodeBuild rather than CodePipeline is the defect: CodeBuild performs a build and cannot provide the staged source, approval, and deploy phases that the requirement's review, approval, and rollback behavior depends on, so a commit would not be gated before its changes took effect. B creates the same CodeCommit-stored templates but configures a CodePipeline pipeline that the security team invokes manually, supplying parameters at each start. Requiring a person to start every deployment means a guardrail could not be applied through an approved commit alone and adds a manual step for every change, which weakens the approval property and increases operational effort. D configures a CodePipeline pipeline invoked by an EventBridge rule on PutObject events to an S3 bucket, and stores the templates in that bucket. As c87b433 pointed out, storing the source templates in S3 rather than a version-controlled repository removes the version control, review, and rollback capability the requirement explicitly demands. C is correct.

Community Comment Notes

Community voted C (83), with D a minority (17). Srikantha explained that version control is managed through CodeCommit so guardrail changes can be reviewed and rolled back if necessary, and that approval and governance are built into the process. uncledana described C as the most efficient and scalable option for automating guardrails while meeting the requirements for version control, approval, and rollback. c87b433 was the sole dissenter, noting that option D uses PutObject events to an S3 bucket to invoke CodePipeline whereas the solution should be invoked by the security team's commits, which is precisely the versioning objection. No alternative received majority support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide