DOP-C02 Configuration Management and IaC Practice Question
A company manages its AWS infrastructure using AWS CloudFormation templates stored in an Amazon S3 bucket. The DevOps team needs to enforce that all new CloudFormation stacks are created only from templates that have been validated by AWS CloudFormation Guard. The team wants to integrate this validation into their existing CI/CD pipeline built with AWS CodePipeline. Which approach will meet these requirements with the LEAST operational overhead?
⚠ Common exam trap
The trap here is assuming that CloudFormation change sets or drift detection can enforce template policy validation, when they actually only show differences or detect drift after deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a CodeBuild action to the pipeline that runs `cfn-guard validate` against the template and fails the build if validation fails.
Running AWS CloudFormation Guard in CodeBuild is the most efficient way to enforce template validation. Guard integrates seamlessly with CodePipeline, and CodeBuild provides a managed environment where you can install and execute `cfn-guard validate`. This ensures that only validated templates proceed to deployment, with minimal operational effort compared to custom Lambda functions or post-deployment checks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a CodeBuild action to the pipeline that runs `cfn-guard validate` against the template and fails the build if validation fails.
Why this is correct
AWS CloudFormation Guard is a policy-as-code tool that can be run in CodeBuild. Integrating `cfn-guard validate` as a build step ensures templates are validated before deployment, and the pipeline stops on failure. This requires minimal setup: install Guard in the build environment, run the command, and check the exit code. It is a native, serverless approach with no infrastructure to manage.
- ✗
Use AWS CloudFormation change sets to preview changes and require manual approval before execution.
Why it's wrong here
Change sets show the impact of stack updates but do not validate templates against policy rules like Guard. They are useful for reviewing resource changes but do not enforce template compliance. Manual approval adds a human step, increasing operational overhead and not providing automated validation. This does not meet the requirement to validate templates with Guard.
- ✗
Enable AWS CloudFormation drift detection on all stacks and automatically remediate any drift using AWS Systems Manager Automation.
Why it's wrong here
Drift detection identifies differences between the actual stack configuration and the expected template, but it does not validate templates before stack creation. It operates after resources are deployed, so it cannot prevent non-compliant templates from being used. Remediation via Systems Manager adds complexity and does not enforce template validation at creation time.
- ✗
Configure an AWS Lambda function that downloads the template and runs `cfn-guard validate`, then triggers the pipeline only if validation succeeds.
Why it's wrong here
While Lambda can run custom code, it introduces additional operational overhead: you must package the Guard binary, manage permissions, and handle invocation from the pipeline. This is more complex than using CodeBuild, which already provides a managed build environment. Lambda also has time and size limits that may hinder large template validation, making it less suitable for this scenario.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.