Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company manages its AWS infrastructure using AWS CloudFormation templates stored in an Amazon S3 bucket. The DevOps team needs to enforce that all new CloudFormation stacks are created only from templates that have been validated by AWS CloudFormation Guard. The team wants to integrate this validation into their existing CI/CD pipeline built with AWS CodePipeline. Which approach will meet these requirements with the LEAST operational overhead?

⚠ Common exam trap

The trap here is assuming that CloudFormation change sets or drift detection can enforce template policy validation, when they actually only show differences or detect drift after deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a CodeBuild action to the pipeline that runs `cfn-guard validate` against the template and fails the build if validation fails.

Running AWS CloudFormation Guard in CodeBuild is the most efficient way to enforce template validation. Guard integrates seamlessly with CodePipeline, and CodeBuild provides a managed environment where you can install and execute `cfn-guard validate`. This ensures that only validated templates proceed to deployment, with minimal operational effort compared to custom Lambda functions or post-deployment checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a CodeBuild action to the pipeline that runs `cfn-guard validate` against the template and fails the build if validation fails.

    Why this is correct

    AWS CloudFormation Guard is a policy-as-code tool that can be run in CodeBuild. Integrating `cfn-guard validate` as a build step ensures templates are validated before deployment, and the pipeline stops on failure. This requires minimal setup: install Guard in the build environment, run the command, and check the exit code. It is a native, serverless approach with no infrastructure to manage.

  • ✗

    Use AWS CloudFormation change sets to preview changes and require manual approval before execution.

    Why it's wrong here

    Change sets show the impact of stack updates but do not validate templates against policy rules like Guard. They are useful for reviewing resource changes but do not enforce template compliance. Manual approval adds a human step, increasing operational overhead and not providing automated validation. This does not meet the requirement to validate templates with Guard.

  • ✗

    Enable AWS CloudFormation drift detection on all stacks and automatically remediate any drift using AWS Systems Manager Automation.

    Why it's wrong here

    Drift detection identifies differences between the actual stack configuration and the expected template, but it does not validate templates before stack creation. It operates after resources are deployed, so it cannot prevent non-compliant templates from being used. Remediation via Systems Manager adds complexity and does not enforce template validation at creation time.

  • ✗

    Configure an AWS Lambda function that downloads the template and runs `cfn-guard validate`, then triggers the pipeline only if validation succeeds.

    Why it's wrong here

    While Lambda can run custom code, it introduces additional operational overhead: you must package the Guard binary, manage permissions, and handle invocation from the pipeline. This is more complex than using CodeBuild, which already provides a managed build environment. Lambda also has time and size limits that may hinder large template validation, making it less suitable for this scenario.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.