Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company is using AWS Elastic Beanstalk with a custom platform. They need to install a third-party agent on all instances. The agent requires a configuration file that contains sensitive credentials. How should the DevOps engineer provide the configuration file to the agent?

⚠ Common exam trap

It's easy for candidates to choose Option A (user data) because it seems like a simple provisioning step, but they overlook that user data is not encrypted and is visible in the EC2 console, making it unsuitable for secrets, whereas .ebextensions with S3 and IAM roles provide a secure, auditable method that aligns with the AWS shared responsibility model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use .ebextensions configuration files to download the configuration from a secure S3 bucket using an IAM instance role.

Ebextensions configuration files allow you to run custom commands and scripts during instance provisioning, and by combining this with an IAM instance role that grants read access to a secure S3 bucket, you can securely download the sensitive configuration file without embedding credentials in the source code or user data. This approach follows AWS best practices for handling secrets by avoiding hard-coded credentials and leveraging IAM roles for temporary, scoped access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use instance user data to write the configuration file during instance launch.

    Why it's wrong here

    User data scripts are executed only at instance launch and are not integrated with Elastic Beanstalk's configuration deployment lifecycle, so they are not a supported or maintainable mechanism for custom platform configuration; the platform's own configuration hooks should be used instead.

  • ✗

    Embed the configuration file in the application source code and deploy it with the application.

    Why it's wrong here

    Embedding the configuration file in the application source code exposes sensitive credentials to any developer or system that can access the repository or source bundle, and it creates a dangerous coupling between application deploys and credential rotation. This approach violates security best practices by storing secrets in code rather than using a dedicated secrets store or instance role-based access.

  • ✓

    Use .ebextensions configuration files to download the configuration from a secure S3 bucket using an IAM instance role.

    Why this is correct

    .ebextensions files are processed by Elastic Beanstalk during environment creation and every instance deployment, allowing you to use a container command to copy the configuration from a private S3 bucket. Using an IAM instance role with a least-privilege policy scoped to that bucket keeps credentials out of code, and the configuration can be updated independently of the application.

  • ✗

    Use AWS Systems Manager Run Command to distribute the configuration file after instances are launched.

    Why it's wrong here

    Systems Manager Run Command can push the file to running instances, but it is not invoked automatically when Elastic Beanstalk scales out or replaces an unhealthy instance, so new instances would miss the configuration unless you build a custom automation to detect and invoke it. This introduces a race condition between instance availability and configuration deployment, and it is not part of the Elastic Beanstalk provisioning process.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.