Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Exhibit

Refer to the exhibit.

Error log from CloudFormation stack creation:
"Property validation failure: The value for parameter "SecurityGroupIds" is not a list."

A CloudFormation template includes the following resource:

MySecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: My security group SecurityGroupIngress: - IpProtocol: tcp FromPort: 443 ToPort: 443 CidrIp: 0.0.0.0/0

MyInstance: Type: AWS::EC2::Instance Properties: ImageId: ami-0abcdef1234567890 InstanceType: t2.micro SecurityGroupIds: !Ref MySecurityGroup

The stack creation fails with the error shown. What is the cause?

⚠ Common exam trap

Many exam-takers assume `!Ref` automatically returns a list when the property expects one, but CloudFormation does not coerce scalar values into lists; you must explicitly provide a list literal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SecurityGroupIds property must be a list, but !Ref returns a single value.

The error occurs because the `SecurityGroupIds` property expects a list of security group IDs, but the `!Ref` intrinsic function returns a single security group ID (a string), not a list. In CloudFormation, `!Ref` for a security group returns its ID as a scalar value, so wrapping it in a list (e.g., `[!Ref MySecurityGroup]`) is required to satisfy the `List<String>` type constraint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SecurityGroupIds property must be a list, but !Ref returns a single value.

    Why this is correct

    The `SecurityGroupIds` property of an EC2 instance is typed as a list of security group IDs. When you use `!Ref` on a security group resource, CloudFormation resolves it to the security group's physical ID as a single string, not an array. Because the property requires a `List<AWS::EC2::SecurityGroup::Id>`, passing a bare `!Ref` causes a type-validation failure. To fix it, you must wrap the reference in a list literal, e.g., `SecurityGroupIds: [!Ref MySecurityGroup]`, or use `Fn::Split` if composing from a string.

  • ✗

    The SecurityGroupIds property must be a list of security group names, not IDs.

    Why it's wrong here

    The `SecurityGroupIds` property explicitly expects security group IDs, not names; group names are only used with the separate `SecurityGroupNames` property, which is not applicable when the instance is launched into a VPC. Even if the template passed a group name, the property would still reject it because it is defined as a list of IDs. The actual CloudFormation error is caused by supplying a scalar value (a string) where a list is required, not by a name-versus-ID confusion, so this option misidentifies the root cause.

  • ✗

    The security group ingress rule is invalid because it allows all traffic.

    Why it's wrong here

    The ingress rule in the template allows HTTPS traffic on port 443 from the entire internet (`0.0.0.0/0`), which is a common and fully valid configuration for a public web server. CloudFormation treats security group ingress rules as independent resources, and an allowed all-traffic rule would not trigger a validation error for an EC2 instance's `SecurityGroupIds`. The reported error specifically names `SecurityGroupIds`, indicating a type mismatch in the instance resource, not a problem with the ingress rule's allow-all CIDR.

  • ✗

    The ImageId is missing, so the security group validation fails first.

    Why it's wrong here

    Omission of `ImageId` would produce a distinct validation error such as "Property ImageId is required" or a deployment-time failure when the instance resource is processed. CloudFormation performs property type checks while parsing the template, and the error message explicitly references `SecurityGroupIds`, proving the parser already reached that property and found a type mismatch. A missing `ImageId` is a separate, later-stage requirement check and cannot be the first validation failure described in the question.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.