DVA-C02 Troubleshooting and Optimization Practice Question
A company uses AWS CloudFormation to deploy a stack that includes an RDS MySQL instance. During an update, the stack fails with a 'DELETE_FAILED' status on a security group resource. The security group has a dependency on the RDS instance. What is the MOST likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RDS instance is not fully deleted because of a deletion protection flag.
The most likely cause is that the RDS instance has deletion protection enabled, preventing it from being deleted even when CloudFormation attempts to delete it. The security group depends on the RDS instance, so if the RDS instance cannot be deleted, the security group also fails to delete, resulting in a DELETE_FAILED status. Option A correctly identifies this. Option B is incorrect because a self-referencing rule would not cause a delete failure. Option C is incorrect because manual deletion is not required; the issue is with the RDS instance. Option D is incorrect because the security group being attached to an external EC2 instance would cause a different error, not a dependency-related failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The RDS instance is not fully deleted because of a deletion protection flag.
Why this is correct
If the RDS instance has the DeletionProtection attribute set to true, CloudFormation's attempt to delete or replace that instance during the stack update silently fails, leaving the instance running and still attached to the security group's ENI, which in turn prevents the security group from being deleted since AWS will not remove a security group that is still in use by an active resource.
- ✗
The security group has a rule that references itself.
Why it's wrong here
A security group rule that references itself as a source (a common pattern for allowing intra-group communication) does not create a deletion dependency issue on its own, because CloudFormation and EC2 can delete a self-referencing security group without needing to first remove the self-referencing rule.
- ✗
The security group must be deleted manually before updating the stack.
Why it's wrong here
CloudFormation is designed to fully manage the lifecycle of stack resources, including deletions during updates and replacements, based on the dependency graph it builds from the template; requiring manual deletion outside the stack would defeat the purpose of using infrastructure as code and is not the expected or standard workflow.
- ✗
The security group is attached to an EC2 instance outside the stack.
Why it's wrong here
If an EC2 instance entirely outside the stack were using the security group, the DELETE_FAILED error message would typically reference that instance's ENI or ID directly as the blocking dependency, rather than pointing back to the RDS resource defined within the same stack as described in this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.