AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy

A company is implementing a new CI/CD pipeline using AWS CodePipeline. The security team mandates that all deployments must be approved by a security engineer before proceeding to production. How can a DevOps engineer implement this requirement MOST effectively within CodePipeline?

  1. AUse AWS Step Functions to orchestrate a workflow that includes a human approval task.
  2. BIntegrate AWS Security Hub into CodePipeline to automatically block deployments lacking security approval.
  3. CConfigure an AWS Lambda function to send an approval request to the security team and pause the pipeline.
  4. DAdd a manual approval action in CodePipeline before the production deployment stage.
Show answer & explanation

Correct answer: D. Add a manual approval action in CodePipeline before the production deployment stage.

CodePipeline provides a built-in manual approval action specifically designed for scenarios where human intervention, such as a security team's sign-off, is required before a pipeline stage can proceed.

Why the other options are wrong

  • A. Step Functions can orchestrate complex workflows, but a simple manual approval is a native CodePipeline feature.
  • B. AWS Security Hub aggregates findings and does not directly provide a mechanism for manual approval within a CodePipeline workflow.
  • C. While possible, this is over-engineering for a feature that CodePipeline natively supports.

CodePipeline Manual Approval

A CodePipeline action type that pauses the pipeline execution at a specific stage, requiring a designated user or group to manually approve or reject the continuation of the pipeline.

  • Integrates directly into CodePipeline stages.
  • Sends notifications (e.g., via SNS) for approval requests.
  • Provides an approval URL in the AWS Console.

Memory trick: To 'gate' the 'pipeline', use the 'manual' 'switch'.

More Security and Compliance questions