DVA-C02 Deployment Practice Question
A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to deploy updates to the production environment gradually and automatically roll back if health checks fail. Which AWS service and deployment configuration should the engineer use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CodeDeploy with a canary deployment and a CloudWatch alarm to trigger automatic rollback.
AWS CodeDeploy with a canary deployment (option C) is the right choice because CodeDeploy natively supports gradual traffic shifting to a new version and integrates with CloudWatch alarms to automatically roll back when health checks or alarms fail, which directly matches the requirement for gradual deployment with automatic rollback. Canary deployments shift a small percentage of traffic first, then the rest, minimizing blast radius if something goes wrong. Option A is wrong because CloudFormation blue/green handles infrastructure replacement but does not provide CodeDeploy-style gradual traffic shifting with alarm-driven automatic rollback for application deployments. Option B is wrong because Elastic Beanstalk rolling updates replace instances in batches but do not offer the same alarm-triggered automatic rollback semantics as CodeDeploy. Option D is wrong because CodePipeline is an orchestration service, and a manual approval step actually blocks automation rather than enabling gradual automated deployment with rollback.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudFormation with a blue/green deployment and a CloudWatch alarm to trigger rollback.
Why it's wrong here
AWS CloudFormation is primarily an infrastructure-as-code service for provisioning and managing AWS resources, including the creation of blue and green environments. While it can orchestrate the deployment of resources for a blue/green strategy, CloudFormation itself does not inherently manage application traffic shifting or provide built-in logic for automatically rolling back an application based on real-time application health metrics from a CloudWatch alarm during a cutover. Manual intervention or integration with other services would be required for such a rollback.
- ✗
Use AWS Elastic Beanstalk with a rolling update and a CloudWatch alarm to trigger rollback.
Why it's wrong here
AWS Elastic Beanstalk offers various deployment policies, including rolling updates, which replace instances in batches. However, rolling updates do not support advanced traffic shifting capabilities like canary deployments, where a small percentage of traffic is gradually introduced to the new version. While Elastic Beanstalk can perform basic rollbacks on deployment failures, it lacks native integration for automatic application-level rollbacks triggered by CloudWatch alarms monitoring application health during a gradual, canary-like traffic shift.
- ✓
Use AWS CodeDeploy with a canary deployment and a CloudWatch alarm to trigger automatic rollback.
Why this is correct
AWS CodeDeploy is purpose-built for automating application deployments and supports advanced strategies like canary deployments. With a canary deployment, CodeDeploy incrementally shifts traffic to the new application version, allowing a small subset of users to experience it first. If a pre-configured CloudWatch alarm, monitoring critical application metrics such as error rates or latency, triggers during this phased rollout, CodeDeploy can automatically initiate a rollback to the previously stable application version, effectively minimizing impact.
- ✗
Use AWS CodePipeline with a manual approval step and a CloudWatch alarm to trigger rollback.
Why it's wrong here
AWS CodePipeline is an orchestration service that automates the various stages of a CI/CD workflow, such as build, test, and deploy. While it can integrate with CloudWatch alarms to pause a pipeline or trigger notifications, CodePipeline itself does not directly execute deployment strategies like canary releases or perform automatic rollbacks of application code based on application health metrics. A manual approval step would halt the pipeline, requiring human intervention rather than an automatic, health-check-driven rollback.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.