Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation StackSets to deploy a common security group across multiple accounts in an AWS Organization. The security group must allow inbound traffic from the organization's central VPN CIDR range. The VPN CIDR range is stored in AWS Systems Manager Parameter Store. How should the engineer reference this parameter in the StackSet template to ensure the value is resolved at deployment time?

⚠ Common exam trap

Many candidates confuse dynamic references with CloudFormation parameters or intrinsic functions like Ref and Fn::GetAtt, not realizing that {{resolve:ssm:...}} is a special syntax that directly retrieves SSM parameter values without requiring a resource or parameter declaration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the dynamic reference '{{resolve:ssm:/org/vpn/cidr}}' in the template.

CloudFormation dynamic references ({{resolve:ssm:/org/vpn/cidr}}) allow you to retrieve the current value of an SSM Parameter Store parameter at stack deployment time, without needing to pass it as a parameter or create a separate resource. This ensures the security group rule always uses the latest VPN CIDR value stored in Parameter Store, even if the CIDR changes between deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Fn::ImportValue with an export from another stack that reads the parameter.

    Why it's wrong here

    A: This option is incorrect because the Ref function is used to refer to a parameter defined in the template's Parameters section, not to directly access an SSM parameter. You would need to pass the parameter value manually.

  • ✓

    Use the dynamic reference '{{resolve:ssm:/org/vpn/cidr}}' in the template.

    Why this is correct

    The `{{resolve:ssm:/org/vpn/cidr}}` dynamic reference resolves the Parameter Store value at deployment time, satisfying the requirement that the CIDR is fetched when the StackSet instantiates stacks. Unlike hard-coded values or parameters passed manually, it retrieves the current stored value per account deployment, keeping the security group rule consistent with the central VPN range.

  • ✗

    Use the Ref function on the parameter name as a CloudFormation parameter.

    Why it's wrong here

    C: This option is incorrect because Fn::GetAtt returns attributes of a resource created within the same stack. To use it, you would need to create an AWS::SSM::Parameter resource, which would duplicate the parameter and not reference the existing one.

  • ✗

    Use Fn::GetAtt to retrieve the parameter value from an AWS::SSM::Parameter resource.

    Why it's wrong here

    D: This option is incorrect because Fn::ImportValue requires an exported value from another stack. You cannot directly import an SSM parameter; you would need a stack that exports the parameter value, which adds unnecessary complexity.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.