DOP-C02 Configuration Management and IaC Practice Question
A company is using AWS Elastic Beanstalk with a custom platform. They need to install a third-party agent on all instances. The agent requires a configuration file that contains sensitive credentials. How should the DevOps engineer provide the configuration file to the agent?
⚠ Common exam trap
It's easy for candidates to choose Option A (user data) because it seems like a simple provisioning step, but they overlook that user data is not encrypted and is visible in the EC2 console, making it unsuitable for secrets, whereas .ebextensions with S3 and IAM roles provide a secure, auditable method that aligns with the AWS shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use .ebextensions configuration files to download the configuration from a secure S3 bucket using an IAM instance role.
Ebextensions configuration files allow you to run custom commands and scripts during instance provisioning, and by combining this with an IAM instance role that grants read access to a secure S3 bucket, you can securely download the sensitive configuration file without embedding credentials in the source code or user data. This approach follows AWS best practices for handling secrets by avoiding hard-coded credentials and leveraging IAM roles for temporary, scoped access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use instance user data to write the configuration file during instance launch.
Why it's wrong here
User data scripts are executed only at instance launch and are not integrated with Elastic Beanstalk's configuration deployment lifecycle, so they are not a supported or maintainable mechanism for custom platform configuration; the platform's own configuration hooks should be used instead.
- ✗
Embed the configuration file in the application source code and deploy it with the application.
Why it's wrong here
Embedding the configuration file in the application source code exposes sensitive credentials to any developer or system that can access the repository or source bundle, and it creates a dangerous coupling between application deploys and credential rotation. This approach violates security best practices by storing secrets in code rather than using a dedicated secrets store or instance role-based access.
- ✓
Use .ebextensions configuration files to download the configuration from a secure S3 bucket using an IAM instance role.
Why this is correct
.ebextensions files are processed by Elastic Beanstalk during environment creation and every instance deployment, allowing you to use a container command to copy the configuration from a private S3 bucket. Using an IAM instance role with a least-privilege policy scoped to that bucket keeps credentials out of code, and the configuration can be updated independently of the application.
- ✗
Use AWS Systems Manager Run Command to distribute the configuration file after instances are launched.
Why it's wrong here
Systems Manager Run Command can push the file to running instances, but it is not invoked automatically when Elastic Beanstalk scales out or replaces an unhealthy instance, so new instances would miss the configuration unless you build a custom automation to detect and invoke it. This introduces a race condition between instance availability and configuration deployment, and it is not part of the Elastic Beanstalk provisioning process.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.