QuestionQ60

Security and Compliance

A DevOps engineer is working on a project hosted on Amazon Linux that has failed a security review. The DevOps manager has been asked to review the company’s buildspec.yaml file for an AWS CodeBuild project and make recommendations. The buildspec.yaml file is configured as follows:

Question Image

Which changes should be recommended to comply with AWS security best practices?

Choose three
Explanation

AWS CodeBuild strongly discourages storing sensitive values—especially AWS access key IDs—in environment variables because they can be displayed in plaintext. The build should instead obtain its permissions through a least-privilege CodeBuild service role. Database passwords should be stored as Systems Manager Parameter Store SecureString values, which are encrypted with AWS KMS. Systems Manager Run Command securely manages configured instances without directly logging in through SSH or distributing an SSH private key.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!