DevOps CI/CD Pipeline Design & Implementation Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 DevOps CI/CD Pipeline Design & Implementation flashcards as text
A team wants to validate that their Terraform infrastructure code follows company standards before any deployment. Which pipeline stage pattern accomplishes this with minimal custom tooling?
Answer: Use CodeBuild to run terraform validate and tflint as a pre-deployment stage in CodePipeline
Running terraform validate and linting tools in a CodeBuild stage catches syntax and policy violations early in the pipeline before any infrastructure is provisioned.
Which metric should you monitor to measure the DevOps practice of Continuous Delivery pipeline health, representing the time from a code commit to a production deployment?
Answer: Lead time for changes
Lead time for changes measures the elapsed time from a code commit to when that change is running in production, directly reflecting CI/CD pipeline efficiency.
A CodePipeline stage fails intermittently due to a flaky integration test. What is the recommended approach to handle transient failures without blocking the pipeline?
Answer: Use CodePipeline's built-in stage retry functionality to re-run the failed stage without restarting the entire pipeline
CodePipeline supports manual stage retry, allowing operators to re-run only the failed stage using the existing artifacts without re-executing earlier stages.
An organization wants to enforce that no one can manually push directly to the CodeCommit main branch—all changes must go through a pull request and CodeBuild status check. What enforces this?
Answer: An IAM policy denying the codecommit:GitPush action on the main branch combined with a CodeCommit approval rule template
An IAM deny policy on GitPush for the protected branch prevents direct pushes, while CodeCommit approval rule templates require pull request approvals and status checks before merging.
A team needs their CodePipeline to deploy to resources inside a private VPC with no internet access. What configuration is required for CodeBuild to reach those resources?
Answer: Configure the CodeBuild project to run inside the VPC by specifying the VPC ID, subnets, and security groups
CodeBuild projects support VPC configuration where you specify the VPC, private subnets, and security groups, allowing build containers to access private resources without internet routing.
Which AWS CodeDeploy deployment configuration would you choose to deploy to all instances simultaneously, accepting higher risk for the fastest possible deployment speed?
Answer: CodeDeployDefault.AllAtOnce
CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which is the fastest option but has the highest blast radius if the deployment fails.
A company wants to automatically trigger their CodePipeline whenever a new version of a third-party container image is pushed to Amazon ECR. Which service detects this event and starts the pipeline?
Answer: Amazon EventBridge rule matching the ECR image push event and invoking CodePipeline
Amazon EventBridge receives ECR image push events and can trigger a CodePipeline StartPipelineExecution API call, enabling near-real-time pipeline execution on new image versions.