DVA-C02 Deployment Practice Question
Network Topology
Refer to the exhibit. A developer attempted to update a CloudFormation stack that includes an EC2 instance. The update failed and the stack is rolling back. The event shows that the EC2 instance update failed with reason 'Resource update cancelled: stack update cancelled'. What is the most likely cause of this failure?
⚠ Common exam trap
DVA-C02 often tests whether candidates can distinguish between IAM authorization failures (Access Denied) and CloudFormation stack-policy denials (Resource update cancelled) — the wording 'cancelled' is the key signal for a stack policy, not permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A stack policy is preventing updates to the EC2 instance resource.
A CloudFormation stack policy is an explicit guardrail that denies Update:Modify (or Update:Replace) actions on specified resources. When the update attempts to modify the EC2 instance, the policy blocks the change, CloudFormation cancels the resource update, and the stack begins rolling back — producing exactly the 'Resource update cancelled: stack update cancelled' event. This is the only option that directly produces a cancellation rather than an authorization, template, or runtime-state error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A stack policy is preventing updates to the EC2 instance resource.
Why this is correct
CloudFormation stack policies are JSON documents that define which resources within a stack can be updated or deleted. If a stack policy is in place and explicitly denies an update action (e.g., "Update": "Deny") on a specific EC2 instance resource, any attempt to modify that resource will be rejected by CloudFormation. This rejection manifests as a "cancelled" status for the update operation, as the service is explicitly prevented from proceeding with the requested change due to the policy's enforcement.
- ✗
The IAM user does not have permission to update EC2 instances.
Why it's wrong here
If the IAM user attempting the CloudFormation stack update lacked the necessary permissions to modify EC2 instances (e.g., ec2:ModifyInstanceAttribute), CloudFormation would typically return an AccessDenied error. This error explicitly indicates an authorization failure at the IAM level, preventing the operation from even starting or progressing. A "cancelled" status, however, implies that the CloudFormation service itself initiated the cancellation, often due to an internal policy or condition rather than an external IAM authorization failure.
- ✗
The template has a missing required parameter for the EC2 instance.
Why it's wrong here
CloudFormation performs a rigorous validation check on the template before initiating any stack update or creation. If the updated template were missing a required parameter for the EC2 instance resource, such as an ImageId or InstanceType, the validation process would fail immediately. This would result in a ValidationError or similar message during the initial template processing phase, long before the update operation could reach a "cancelled" state.
- ✗
The EC2 instance is in a stopped state and cannot be updated.
Why it's wrong here
CloudFormation is capable of updating EC2 instances regardless of their operational state (running, stopped, or pending), as long as the requested update is valid for the resource. For example, changing an instance's InstanceType or Tags can be done while it's stopped. If an update *were* genuinely incompatible with the instance's current state, the error message would be specific to that incompatibility, such as an API error from the EC2 service itself, rather than a generic "cancelled" status from CloudFormation.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.