DOP-C02 SDLC Automation Practice Question
A company deploys a serverless application using AWS SAM. The application includes an API Gateway REST API and multiple Lambda functions. The team wants to implement canary deployments for the API to gradually shift traffic to a new version. Which SAM template configuration should be used?
⚠ Common exam trap
A common mix-up: candidates confuse `AutoPublishAlias` with canary deployments, assuming that publishing a new version and pointing an alias to it automatically shifts traffic gradually, when in fact it requires an explicit `DeploymentPreference` with a canary type to enable traffic shifting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the CanaryDeployment property on the Serverless::Function resource with a DeploymentPreference
AWS SAM's `CanaryDeployment` property on the `AWS::Serverless::Function` resource, combined with a `DeploymentPreference` of type `Canary10Percent5Minutes`, enables gradual traffic shifting for API Gateway integrations. This configuration automatically creates a Lambda alias, publishes new versions, and shifts a percentage of API traffic to the new version over a specified time window, all without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the CanaryDeployment property on the Serverless::Function resource with a DeploymentPreference
Why this is correct
The SAM CanaryDeployment property, when paired with a DeploymentPreference such as 'Canary10Percent5Minutes', delegates to AWS CodeDeploy to manage a gradual traffic shift. CodeDeploy publishes a new Lambda version, then adjusts the alias's routing configuration to send only 10% of live invocations to the new version for a 5-minute observation period, and finally shifts the remaining 90% after the interval succeeds. It also supports CloudWatch alarm-based automatic rollback, making it the only option here that provides a managed, gradual, and rollback-capable canary release on Lambda.
- ✗
Create multiple Lambda function versions and use API Gateway stage variables to switch between them
Why it's wrong here
API Gateway stage variables are simply environment-specific variables that the API integration can reference (for example, as part of a Lambda function ARN or alias name). Changing a stage variable during an API deployment switches the function version atomically and immediately for all in-flight and new requests; there is no built-in mechanism to send a small percentage of traffic to a new version over time. While you could manually orchestrate incremental changes to stage variables, that would be a custom, non-automated process with no monitoring or automatic rollback, so it does not satisfy the canary deployment requirement.
- ✗
Define the Lambda function with AutoPublishAlias: live and set the API Gateway integration to point to the alias
Why it's wrong here
AutoPublishAlias: live makes SAM automatically create a new Lambda version on every stack update and point the 'live' alias at it immediately. All invocations that use that alias are routed to the new code the moment the update completes, so traffic shifts from old to new in a single, full cutover. It does not utilize Lambda's weighted alias routing (RoutingConfig) nor CodeDeploy's deployment process, so there is no gradual percentage-based traffic shift and no automated rollback; this is exactly the all-at-once behavior the question asks to avoid.
- ✗
Use AWS CloudFormation's UpdatePolicy with AutoScalingRollingUpdate
Why it's wrong here
UpdatePolicy with AutoScalingRollingUpdate is a CloudFormation policy designed for EC2 Auto Scaling groups, where it controls how many instances at a time are terminated, updated, and re-registered during a stack update. AWS Lambda functions are serverless and have no EC2 instances to manage; CloudFormation cannot use this policy to affect Lambda invocation routing. Therefore, this option is not only the wrong tool for canary deployments, it is entirely inapplicable to Lambda functions and would be ignored or fail during update.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.