Build a CodePipeline CI/CD flow with CodeBuild, SNS alerts, CDK feature flags, and manual approval

Answer Correct answer: A — Use CodeBuild for tests and scans, EventBridge with SNS for failure alerts, AWS CDK with a manifest for feature flags, and a manual approval stage.

A company is using AWS CloudFormation as its deployment tool for all applications. It stages all application binaries and templates within Amazon S3 buckets with versioning enabled. Developers have access to an Amazon EC2 instance that hosts the integrated development environment (IDE). The developers download the application binaries from Amazon S3 to the EC2 instance, make changes, and upload the binaries to an S3 bucket after running the unit tests locally. The developers want to improve the existing deployment mechanism and implement CI/CD using AWS CodePipeline. The developers have the following requirements: • Use AWS CodeCommit for source control. • Automate unit testing and security scanning. • Alert the developers when unit tests fail. • Turn application features on and off, and customize deployment dynamically as part of CI/CD. • Have the lead developer provide approval before deploying an application. Which solution will meet these requirements?

  1. Use AWS CodeBuild to run unit tests and security scans. Use an Amazon EventBridge rule to send Amazon SNS alerts to the developers when unit tests fail. Write AWS Cloud Development Kit (AWS CDK) constructs for different solution features, and use a manifest file to tum features on and off in the AWS CDK application. Use a manual approval stage in the pipeline to allow the lead developer to approve applications. Correct Answer
  2. Use AWS Lambda to run unit tests and security scans. Use Lambda in a subsequent stage in the pipeline to send Amazon SNS alerts to the developers when unit tests fail. Write AWS Amplify plugins for different solution features and utilize user prompts to tum features on and off. Use Amazon SES in the pipeline to allow the lead developer to approve applications.
  3. Use Jenkins to run unit tests and security scans. Use an Amazon EventBridge rule in the pipeline to send Amazon SES alerts to the developers when unit tests fail Use AWS CloudFormation nested stacks for different solution features and parameters to turn features on and off. Use AWS Lambda in the pipeline to allow the lead developer to approve applications.
  4. Use AWS CodeDeploy to run unit tests and security scans. Use an Amazon CloudWatch alarm in the pipeline to send Amazon SNS alerts to the developers when unit tests fail. Use Docker images for different solution features and the AWS CLI to turn features on and off. Use a manual approval stage in the pipeline to allow the lead developer to approve applications.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

AWS CDK expresses infrastructure as code with constructs and context parameters, so a manifest file can turn features on and off without maintaining separate templates, and CodePipeline's manual approval action is a first-class stage that pauses the pipeline until an authorised approver acts.

A company uses CloudFormation for all deployments and stages binaries in versioned S3 buckets, with developers working from an EC2-hosted IDE. The developers want to adopt CI/CD with CodePipeline and CodeCommit, automate unit testing and security scanning, alert on test failures, toggle features dynamically as part of the pipeline, and require lead developer approval before deployment.

Using Lambda or Jenkins to run the tests. Lambda is a poor fit for long-running build and test workloads with their own dependency management, and Jenkins is not an AWS-native service in the pipeline, so it adds separate infrastructure to build, secure, and maintain rather than using the managed pipeline stages the requirement is built around.

Community Discussion (6 comments)

ebbff63 👍 10
A- Yes B - No - Lambda not optimal for unit testing c- No - Jenkins needs separate management not part of the AWS native services D - No - CodeDeploy is for deployment, not to run unit tests and security scans
AzureDP900 👍 1
By choosing option A, the developers can meet all of their requirements and implement a robust CI/CD pipeline that integrates with AWS services. Using AWS CodeBuild to run unit tests and security scans meets the requirement of automating these tasks. The use of Amazon EventBridge rules to send SNS alerts when unit tests fail meets the requirement of alerting developers when tests fail. Writing AWS CDK constructs for different solution features allows for dynamic customization of deployment, meeting the requirement of turning features on and off. Using a manifest file to control feature toggling in the AWS CDK application provides a centralized way to manage these changes, making it easier to customize deployment dynamically. The manual approval stage using AWS CodePipeline allows the lead developer to provide approval before deploying an application, meeting this requirement.
0b43291 👍 1 Selected: A
By leveraging AWS CodeBuild, EventBridge, SNS, AWS CDK, and manual approval stages in CodePipeline, Option A provides a comprehensive solution that meets all the requirements for implementing CI/CD using AWS CodePipeline. Option B: AWS Lambda is not suitable for running unit tests and security scans. Additionally, using Amplify plugins and user prompts for feature toggling may not be as flexible as using AWS CDK constructs and a manifest file. Option C: Using Jenkins for unit testing and security scanning introduces an additional tool to manage and maintain. Additionally, using nested stacks and parameters for feature toggling may not be as flexible as using AWS CDK constructs and a manifest file. Option D: AWS CodeDeploy is primarily used for application deployment, not for running unit tests and security scans. Additionally, using Docker images and the AWS CLI for feature toggling may not be as flexible as using AWS CDK constructs and a manifest file.
backbencher2022 👍 1 Selected: A
A is correct option - https://docs.aws.amazon.com/codebuild/latest/userguide/test-reporting.html
ryuhei 👍 1 Selected: A
I think A is the correct answer because I will be testing with codebuild.
5ehjry6sktukliyliuliykutjhy 👍 2 Selected: A
Codebuild looks good

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Each requirement maps onto a specific CodePipeline capability. AWS CodeBuild is the managed build service that runs unit tests and security scans, reporting results as part of the build project, which satisfies the automation requirement without any test infrastructure to host. An EventBridge rule watching for the failure state can publish to an Amazon SNS topic, so developers are alerted when unit tests fail, which satisfies the alerting requirement. Writing AWS CDK constructs for each capability and controlling them from a manifest file means a single code base can turn features on and off as the pipeline runs, which satisfies the dynamic configuration requirement without maintaining parallel CloudFormation templates. Finally a manual approval stage in the pipeline pauses before deployment until the lead developer approves, which satisfies the governance requirement natively.

Why the Other Options Are Wrong

B: AWS Lambda is not a build service, so running unit tests and security scans there means packaging toolchains into functions and managing dependencies and runtimes by hand. Amazon Amplify plugins and user prompts are an application tooling model rather than a pipeline feature toggle mechanism, and Amazon SES is an email service rather than a pipeline approval action. C: Jenkins introduces a self-managed build server outside the AWS-native pipeline, which is a separate system to patch, secure, and integrate. Amazon SES for approval and a Lambda for approval are workarounds for a capability CodePipeline provides as a native manual approval stage, and the CloudWatch alarm is a metric-based trigger rather than a response to a specific test result. D: CodeDeploy performs deployments, it does not run unit tests or security scans, so it cannot satisfy the first requirement. A CloudWatch alarm keyed on a metric again cannot respond to a specific failing test, and Docker images with the AWS CLI are not a feature-flag mechanism.

Community Comment Notes

The community voted 100 to 0 for A, and the top-voted comment addressed every wrong option with a one-line reason: Lambda is not optimal for unit testing, Jenkins needs separate management outside the AWS-native services, and CodeDeploy is for deployment rather than for running unit tests and security scans. Another commenter linked the CodeBuild documentation on test reporting, which is the mechanism that makes the test results visible to the pipeline.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide