โ† All AWS Flashcard Decks

DevOps CI/CD Pipeline Design & Implementation Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 DevOps CI/CD Pipeline Design & Implementation flashcards as text
  1. A company wants to enforce that every container image deployed to ECS was built by their CodeBuild pipeline and has not been tampered with. Which AWS service enforces this?

    Answer: AWS Signer with container image signing and ECR image tag immutability

    AWS Signer can sign container images, and combined with ECR immutable tags and IAM policies, ensures only pipeline-signed images are deployable to ECS.

  2. In a multi-account AWS CI/CD setup, a CodePipeline in the tools account needs to deploy CloudFormation stacks in a production account. What mechanism enables cross-account deployment?

    Answer: Create a cross-account IAM role in the production account and configure CodePipeline to assume it during deployment

    Cross-account deployments require a deployment role in the target account that the pipeline's role in the tools account can assume; the S3 artifact bucket must also grant the target account access.

  3. A pipeline should automatically roll back an ECS service deployment if the average CPU exceeds 80% for 5 minutes after release. Which AWS feature implements this?

    Answer: CodeDeploy deployment group with a CloudWatch alarm configured to trigger automatic rollback

    CodeDeploy deployment groups support CloudWatch alarm-based automatic rollback; if the alarm fires during or after deployment, CodeDeploy reverts to the previous version.

  4. Which CodeBuild environment variable is automatically provided and contains the S3 URL of the input artifact for the current build?

    Answer: CODEBUILD_SRC_DIR

    CODEBUILD_SRC_DIR contains the absolute path of the directory where CodeBuild places the downloaded source (or input artifact) for the build.

  5. A team wants to test infrastructure changes using CloudFormation before deploying to production. Which CodePipeline action type supports deploying a change set for review without executing it?

    Answer: AWS CloudFormation CREATE_CHANGE_SET action followed by a manual approval and EXECUTE_CHANGE_SET action

    The CREATE_CHANGE_SET action generates a CloudFormation change set for review; after a manual approval gate, EXECUTE_CHANGE_SET applies the changes, providing a safe review workflow.

  6. Which AWS CodePipeline action provider allows you to run a custom script or tool that is not natively supported by CodePipeline?

    Answer: Both A and B are valid approaches

    Both CodeBuild (arbitrary script execution in a build container) and Lambda (serverless custom logic) are valid extensibility points for unsupported operations in CodePipeline.

  7. A security team requires that all pipeline artifacts be encrypted with a customer-managed KMS key rather than the default AWS-managed key. Where is this configured?

    Answer: In the CodePipeline pipeline configuration under the artifact store encryption key setting

    CodePipeline's artifact store configuration accepts an optional encryption key field where you specify a customer-managed KMS key ARN to encrypt all pipeline artifacts.