DOP-C02 Configuration Management and IaC Practice Question
A company uses Ansible for configuration management on EC2 instances. They want to ensure that only instances with a specific tag (Environment: Production) are targeted by their playbooks. What is the best way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the AWS EC2 dynamic inventory plugin to filter instances based on tags.
The best approach because the AWS EC2 dynamic inventory plugin allows filtering instances by tags (e.g., 'Environment: Production') at runtime, ensuring only tagged instances are targeted. Option A (adding a 'when' condition) is less efficient as it connects to all instances first. Option B (static inventory) requires manual updates and is not dynamic. Option D (ec2_tag module) is for assigning tags, not selecting instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a 'when' condition in the playbook to check the instance tag at runtime.
Why it's wrong here
A 'when' condition evaluates after the play targets hosts, so untagged instances are still contacted and facts gathered; it filters tasks, not inventory. Tag-based targeting belongs in the inventory or a dynamic inventory plugin. Runtime conditions suit conditional task execution, such as skipping a step on one OS.
- ✗
Maintain a static inventory file listing only Production instances.
Why it's wrong here
A static inventory file cannot reflect tag changes, so newly tagged Production instances are missed and untagged ones remain targeted until manually edited. Dynamic inventories query EC2 tags at runtime, which is the intended mechanism. Static files suit fixed, unchanging hosts where tags play no role.
- ✓
Use the AWS EC2 dynamic inventory plugin to filter instances based on tags.
Why this is correct
The EC2 dynamic inventory plugin queries the AWS API and groups hosts by their tags, so `Environment: Production` becomes a selectable group or filterable host pattern. This satisfies the requirement to target only tagged production instances without maintaining a static inventory file that would drift as instances launch or terminate.
- ✗
Use the ec2_tag module to assign the tag to instances.
Why it's wrong here
The ec2_tag module writes tags onto instances; it does not select which hosts a playbook runs against. Targeting by tag requires a dynamic inventory plugin or the aws_ec2 inventory source, which filters hosts on Environment: Production. ec2_tag is for managing tag metadata itself, not host selection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.