DVA-C02 Deployment Practice Question
A company uses AWS CodePipeline to automate deployments. The pipeline has a source stage that pulls from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CloudFormation. The deploy stage often fails because CloudFormation change sets are not being created. What is the most likely cause?
⚠ Common exam trap
Candidates often overlook the artifact configuration between pipeline stages. If a stage fails because a file or change set cannot be created, verify that the input artifact from the previous stage (CodeBuild) actually contains the required template file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CodeBuild project is not producing the expected output artifacts.
For AWS CloudFormation to create a change set in a CodePipeline deploy stage, it requires an input artifact containing the CloudFormation template file. If the preceding CodeBuild stage is not configured to produce the expected output artifact (or if the template file is omitted from the buildspec's artifacts section), the CloudFormation action will fail because it cannot locate the template to generate the change set.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The CodeBuild project is not producing the expected output artifacts.
Why this is correct
If the CodeBuild project fails to produce the expected output artifacts, or if the artifacts are malformed, the subsequent CloudFormation deploy action would likely fail due to an inability to locate or parse the CloudFormation template or parameter files. This would typically manifest as an input artifact error or a template validation error, rather than a specific 'change set creation failure' which implies the template was found but the operation to create the change set itself failed due to a logical conflict or misconfiguration.
- ✗
The CloudFormation deploy action is configured to use the 'CREATE_AND_EXECUTE' change set mode, but the stack does not exist yet.
Why it's wrong here
The 'CREATE_AND_EXECUTE' change set mode in a CloudFormation deploy action is specifically designed for updating an *existing* CloudFormation stack. If the target stack does not yet exist in the AWS account, this action mode will fail during the change set creation step because there is no stack to compare against or apply changes to. For initial deployments, the action must be configured to create a new stack, typically using the 'CREATE_UPDATE' action mode which handles both initial creation and subsequent updates.
- ✗
The CloudFormation service role is missing.
Why it's wrong here
A missing or improperly configured CloudFormation service role would prevent CloudFormation from obtaining the necessary permissions to interact with AWS resources, leading to an explicit `AccessDenied` or `UnauthorizedOperation` error. This permission-related failure would occur before or during the attempt to create or execute a change set, but it is distinct from a 'change set creation failure' that arises from a logical incompatibility between the requested change set operation and the current state of the stack.
- ✗
The source stage is not configured to detect changes in the S3 bucket.
Why it's wrong here
If the source stage is not configured to detect changes in the S3 bucket, or if no changes occur, the CodePipeline execution simply would not trigger or would not progress past the source stage. Consequently, the deploy stage would never be reached, and no failure related to change set creation could occur. This issue prevents the pipeline from initiating a deployment cycle altogether, rather than causing a failure within a specific action of an active execution.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.