Build a CodePipeline CI/CD flow with CodeBuild, SNS alerts, CDK feature flags, and manual approval
A company is using AWS CloudFormation as its deployment tool for all applications. It stages all application binaries and templates within Amazon S3 buckets with versioning enabled. Developers have access to an Amazon EC2 instance that hosts the integrated development environment (IDE). The developers download the application binaries from Amazon S3 to the EC2 instance, make changes, and upload the binaries to an S3 bucket after running the unit tests locally. The developers want to improve the existing deployment mechanism and implement CI/CD using AWS CodePipeline. The developers have the following requirements: • Use AWS CodeCommit for source control. • Automate unit testing and security scanning. • Alert the developers when unit tests fail. • Turn application features on and off, and customize deployment dynamically as part of CI/CD. • Have the lead developer provide approval before deploying an application. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS CDK expresses infrastructure as code with constructs and context parameters, so a manifest file can turn features on and off without maintaining separate templates, and CodePipeline's manual approval action is a first-class stage that pauses the pipeline until an authorised approver acts.
A company uses CloudFormation for all deployments and stages binaries in versioned S3 buckets, with developers working from an EC2-hosted IDE. The developers want to adopt CI/CD with CodePipeline and CodeCommit, automate unit testing and security scanning, alert on test failures, toggle features dynamically as part of the pipeline, and require lead developer approval before deployment.
Using Lambda or Jenkins to run the tests. Lambda is a poor fit for long-running build and test workloads with their own dependency management, and Jenkins is not an AWS-native service in the pipeline, so it adds separate infrastructure to build, secure, and maintain rather than using the managed pipeline stages the requirement is built around.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Each requirement maps onto a specific CodePipeline capability. AWS CodeBuild is the managed build service that runs unit tests and security scans, reporting results as part of the build project, which satisfies the automation requirement without any test infrastructure to host. An EventBridge rule watching for the failure state can publish to an Amazon SNS topic, so developers are alerted when unit tests fail, which satisfies the alerting requirement. Writing AWS CDK constructs for each capability and controlling them from a manifest file means a single code base can turn features on and off as the pipeline runs, which satisfies the dynamic configuration requirement without maintaining parallel CloudFormation templates. Finally a manual approval stage in the pipeline pauses before deployment until the lead developer approves, which satisfies the governance requirement natively.Why the Other Options Are Wrong
B: AWS Lambda is not a build service, so running unit tests and security scans there means packaging toolchains into functions and managing dependencies and runtimes by hand. Amazon Amplify plugins and user prompts are an application tooling model rather than a pipeline feature toggle mechanism, and Amazon SES is an email service rather than a pipeline approval action. C: Jenkins introduces a self-managed build server outside the AWS-native pipeline, which is a separate system to patch, secure, and integrate. Amazon SES for approval and a Lambda for approval are workarounds for a capability CodePipeline provides as a native manual approval stage, and the CloudWatch alarm is a metric-based trigger rather than a response to a specific test result. D: CodeDeploy performs deployments, it does not run unit tests or security scans, so it cannot satisfy the first requirement. A CloudWatch alarm keyed on a metric again cannot respond to a specific failing test, and Docker images with the AWS CLI are not a feature-flag mechanism.Community Comment Notes
The community voted 100 to 0 for A, and the top-voted comment addressed every wrong option with a one-line reason: Lambda is not optimal for unit testing, Jenkins needs separate management outside the AWS-native services, and CodeDeploy is for deployment rather than for running unit tests and security scans. Another commenter linked the CodeBuild documentation on test reporting, which is the mechanism that makes the test results visible to the pipeline.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →