DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation StackSets to deploy a common security baseline across multiple AWS accounts. They have a new account that needs to be added to the StackSet. The StackSet is configured with self-service permissions and uses a service-managed IAM role. What must be done to include the new account?
⚠ Common exam trap
Watch out — candidates often confuse self-service permissions (which require manual IAM role creation and stack instance management) with service-managed permissions (which rely on AWS Organizations for automatic account and stack instance management), leading them to choose Option A or C incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the new account to the AWS Organization.
When a StackSet uses service-managed permissions, it relies on AWS Organizations to manage accounts. To include a new account, you must add it to the AWS Organization; the StackSet will automatically deploy stack instances to that account based on the specified organizational units (OUs) or accounts. This is because service-managed permissions use a service-linked role created and managed by CloudFormation, not a manually created IAM role in the target account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM role in the new account that trusts the StackSet.
Why it's wrong here
With service-managed permissions, CloudFormation StackSets relies on AWS Organizations to automatically govern target accounts, and the required IAM roles (such as AWSCloudFormationStackSetExecutionRole) are provisioned and assumed by the service on your behalf. Manually creating an IAM role in the new account that trusts the StackSet reflects the self-managed permissions model, which is not what this setup uses. Moreover, creating such a role neither registers the account as a target nor triggers any stack instance deployment, so it does not solve the problem.
- ✗
Create a new StackSet that includes the new account.
Why it's wrong here
Building a new StackSet just to include one new account is unnecessarily disruptive: you would have to redefine the template, parameters, target regions, and IAM bindings, and the existing stack instances would be orphaned from the new StackSet. StackSets are designed to support incremental target changes; you can simply update the existing StackSet's target account list, either by adding the account to the AWS Organization (for automatic deployment) or by directly adding it as a target in the StackSet's account/region configuration. Creating a separate StackSet is therefore redundant and adds operational overhead.
- ✗
Manually create a stack instance for the new account in the StackSet.
Why it's wrong here
With service-managed permissions, StackSets automatically creates stack instances for every account in the AWS Organization that matches the target criteria, so manually creating a stack instance is both unnecessary and premature. If you attempt to manually create an instance for an account that is not yet in the organization, CloudFormation will not treat it as a valid target and the operation will fail or produce an inconsistent deployment state. Furthermore, even after the account is added, manual instance creation is optional because the service automatically provisions the required instances when automatic deployment is enabled.
- ✓
Add the new account to the AWS Organization.
Why this is correct
Service-managed StackSets are tightly integrated with AWS Organizations, so adding the new account to the organization makes it a recognized target account for the StackSet. Once the account is part of the organization, CloudFormation automatically creates and manages stack instances in every configured region for that account, without requiring manual role setup or stack creation. This approach preserves the existing StackSet's configuration and operational tracking, and it is the intended mechanism for onboarding a new account to a service-managed StackSet.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.