DOP-C02 Configuration Management and IaC Practice Question
A company is using AWS CloudFormation to manage its infrastructure. The DevOps team wants to implement drift detection to identify resources that have been modified outside of CloudFormation. Which TWO of the following are correct statements about CloudFormation drift detection?
⚠ Common exam trap
A common mix-up: candidates assume drift detection is automatic or can fix drift, but AWS explicitly requires manual initiation and only provides detection, not remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Drift detection can detect changes to resources such as security groups.
Drift detection can detect changes to resources such as security groups because CloudFormation supports drift detection for a wide range of AWS resources, including EC2 security groups. When drift detection is performed, CloudFormation compares the current configuration of each supported resource in the stack with the expected configuration defined in the stack template. If a security group rule is added or removed outside of CloudFormation (e.g., via the AWS Console or CLI), drift detection will report that resource as drifted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Drift detection is automatically performed every time the stack is updated.
Why it's wrong here
Drift detection is not an automatic side effect of a stack update; CloudFormation only evaluates drift when you explicitly initiate a DetectStackDrift request from the API, CLI, or console. An update operation merely applies changes to resources based on the template, leaving the stack's existing drift status untouched until a new detection run completes. No CloudFormation setting enables automatic drift detection on every update.
- ✗
Drift detection can be performed on nested stacks independently.
Why it's wrong here
Nested stacks cannot be independently targeted by drift detection, because CloudFormation only accepts a root stack as the input to DetectStackDrift. When you run detection on the root stack, the service recursively checks every nested stack in the hierarchy and aggregates results into the root stack's drift status. There is no public API or console workflow to invoke drift detection on a nested stack in isolation.
- ✗
Drift detection automatically reverts any changes to the original template.
Why it's wrong here
Drift detection is a read-only diagnostic operation: it queries the live configuration of each supported resource and compares it against the template's declared properties, then reports statuses such as MODIFIED or DELETED. It never rolls back resources, rewrites configurations, or makes any calling action to change the stack. Remediation must be implemented separately, for example with AWS Config rules or custom automation.
- ✓
Drift detection can detect changes to resources such as security groups.
Why this is correct
Security groups are among the resource types for which CloudFormation compares the live configuration—such as ingress rules, egress rules, and group name/description—against the template. If someone adds or removes a rule out-of-band, drift detection marks the security group as MODIFIED. This makes drift detection useful for catching unauthorized network-level changes to your VPC infrastructure.
- ✓
Drift detection can be performed on a stack at any time.
Why this is correct
Stack owners can start drift detection manually at any point after the stack has reached a completed state, so it is not limited to moments before or after an update. DetectStackDrift returns a detection ID while scanning runs asynchronously, and you can poll for the StackDriftDetectionId result. This allows proactive audits of live infrastructure to catch manual console changes that were never applied through CloudFormation.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.