Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Network Topology
$ aws cloudformation describe-stack-eventsstack-name my-stackRefer to the exhibit."StackEvents": ["StackId": "arn:aws:cloudformation:us-east-1:123456789012:stack/my-stack/...","EventId": "...","StackName": "my-stack","LogicalResourceId": "MyInstance","PhysicalResourceId": "i-0abcd1234efgh5678","ResourceType": "AWS::EC2::Instance","Timestamp": "2025-02-10T12:00:00.000Z","ResourceStatus": "UPDATE_FAILED","ResourceProperties": "{\"ImageId\":\"ami-0abcdef1234567890\",\"InstanceType\":\"t2.micro\"}",

A CloudFormation stack update failed with the error shown. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often confuse a missing AMI error with an IAM permissions error, but the specific error message about 'AMI' not being found directly points to the AMI ID being invalid or unavailable, not to a lack of permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AMI ID specified in the template is incorrect or has been deregistered.

The error message indicates that CloudFormation cannot find the specified AMI. This typically occurs when the AMI ID is incorrect, has been deregistered, or is not available in the region where the stack is being deployed. CloudFormation validates the AMI ID during stack creation or update, and if the AMI does not exist or is inaccessible, the operation fails with a 'Resource creation cancelled' error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The instance type t2.micro is not available in the region.

    Why it's wrong here

    The error message specifically identifies an invalid imageId, not an unsupported instance type. If t2.micro were unavailable in the region, EC2 would return an 'InvalidInstanceType' or 'UnsupportedOperation' error during RunInstances, which is a different validation step from AMI resolution. The t2.micro type is also offered in most AWS regions, making this an unlikely cause.

  • ✗

    The IAM role used by CloudFormation lacks ec2:RunInstances permissions.

    Why it's wrong here

    An IAM permissions failure would surface as an authorization error, such as 'API: ec2:RunInstances Access Denied' or a statement indicating the role 'is not authorized to perform ec2:RunInstances'. The reported error text is an EC2 parameter-validation error for the imageId, which occurs after the request is authenticated and authorized but before instance launch proceeds. Even if the IAM role lacked permissions, CloudFormation would receive a Client.UnauthorizedOperation rather than an invalid AMI ID.

  • ✓

    The AMI ID specified in the template is incorrect or has been deregistered.

    Why this is correct

    The CloudFormation error explicitly states that the imageId is invalid, which is the EC2 API's validation response for an AMI ID that is malformed, deregistered, or not present in the account/region. During a stack update, CloudFormation passes the AMI ID from the template to the EC2 RunInstances API, and EC2 rejects it with an error like 'InvalidAMIID.NotFound' or 'InvalidAMIID.Malformed', causing the stack update to roll back. This commonly happens when a template references a hard-coded AMI that was deregistered or copied from a different region.

  • ✗

    The stack name does not match the existing stack.

    Why it's wrong here

    A stack name mismatch would prevent the update from being accepted by CloudFormation in the first place, generating a 'ValidationError' that the stack does not exist. The scenario describes a stack update that fails on a resource, meaning the stack name was successfully used to locate the existing stack and the update was already in progress. Therefore, the resource-level EC2 error cannot be caused by a stack name mismatch.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.