DOP-C02 Incident and Event Response Practice Question
A company is using AWS CloudFormation to deploy infrastructure. An engineer needs to ensure that any changes to the production stack are reviewed and approved before they are applied. The engineer also wants to prevent unauthorized changes. Which solution should the engineer implement?
⚠ Common exam trap
Watch out — candidates often confuse the purpose of StackSets (multi-account deployment) or CodePipeline (CI/CD pipeline) with the need for a simple change review mechanism, overlooking the direct and built-in capability of CloudFormation Change Sets to preview and require approval before applying changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use CloudFormation Change Sets and require manual approval to execute the change set.
CloudFormation Change Sets allow you to preview how proposed changes to a stack will impact running resources before you apply them. By requiring manual approval to execute the change set, the engineer ensures that all modifications are reviewed and approved, preventing unauthorized changes. This directly meets the requirement for a review-and-approval workflow without introducing unnecessary complexity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use CloudFormation StackSets to manage the production stack across multiple accounts.
Why it's wrong here
StackSets deploy one template across many accounts and Regions; they add no approval gate or change control for a single production stack. They are tempting because they centralise multi-account infrastructure management, which is the right fit when rolling out identical stacks organisation-wide.
- ✓
Use CloudFormation Change Sets and require manual approval to execute the change set.
Why this is correct
Change Sets generate a preview of proposed resource modifications without applying them, and the manual approval step gates execution until reviewers accept. This satisfies the requirement for review before production changes and blocks unauthorised updates.
- ✗
Use AWS Service Catalog to create a product for the stack and require approval for any portfolio changes.
Why it's wrong here
Service Catalog controls provisioning of approved products; it does not intercept updates to an existing production stack, so direct CloudFormation changes bypass approval entirely. It fits governing which products end users may launch, not reviewing stack diffs.
- ✗
Use AWS CodePipeline to deploy the stack and require manual approval at the deploy stage.
Why it's wrong here
CodePipeline manual approval gates a pipeline run, but CloudFormation stack updates can still be applied directly by anyone with permissions, so unauthorised changes remain possible. It suits release orchestration across accounts, not locking down the stack itself.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.