DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation StackSets to deploy resources across multiple accounts and regions. They need to ensure that updates to the stack set are rolled out in a controlled manner, with the ability to roll back if errors occur. Which THREE strategies should they implement? (Choose THREE.)
⚠ Common exam trap
Candidates often confuse the canary deployment concept (Option A) with StackSets' ability to target specific accounts or OUs, but StackSets does not natively support canary rollouts—you would need to implement that manually with separate stack sets or custom automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set a failure tolerance to allow a certain number of stack operation failures before the overall operation fails
Option B is correct because StackSets support a failure tolerance parameter that defines how many stack instance operations may fail before the entire stack set operation is considered failed and rolled back, enabling controlled error handling. Option D is correct because region concurrency (MaximumConcurrentPercentage or a specific number of regions) lets you limit how many regions are updated in parallel, reducing blast radius and allowing controlled rollout across regions. Option E is correct because maximum concurrent accounts controls how many accounts within each region are updated simultaneously, which is the primary mechanism for throttling and controlling the pace of stack set updates. Option A is not correct because CloudFormation StackSets do not provide a native canary deployment feature; controlled rollout is achieved through concurrency and failure tolerance settings rather than a built-in canary mode. Option C is not correct because manually pausing stack instances is not a supported StackSets control mechanism; rollback and failure handling are governed by failure tolerance and concurrency parameters, not manual pausing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a canary deployment strategy by updating only a subset of accounts first
Why it's wrong here
A canary deployment is not a built-in feature of AWS CloudFormation StackSets. StackSet operations deploy to the complete set of target accounts and Regions governed by the deployment options; there is no native mechanism to roll out to a small subset, validate, and then proceed. You could manually create stack instances in a few accounts first, but that is a separate workaround, not a StackSet update strategy.
- ✓
Set a failure tolerance to allow a certain number of stack operation failures before the overall operation fails
Why this is correct
Failure tolerance specifies how many stack instance failures (as an absolute number or a percentage of total stack instances) are acceptable before the entire StackSet operation is considered failed. When this threshold is exceeded, StackSets automatically rolls back all successfully deployed stack instances, allowing you to absorb a limited number of transient errors without halting the whole deployment. This is the primary safety control for managing partial deployment success.
- ✗
Pause stack instances manually if errors are detected
Why it's wrong here
Manual pausing is unsupported for StackSet operations. While you can cancel an in-progress StackSet operation entirely, you cannot pause individual stack instances, inspect errors, and then resume from that point. StackSets execute operations asynchronously and rely on failure tolerance and automatic rollback to handle errors; if issues occur, you must fix the template or parameters and run a new update operation.
- ✓
Configure region concurrency to control how many regions are updated at a time
Why this is correct
Region concurrency is controlled by the RegionConcurrencyType parameter, which you set to SEQUENTIAL or PARALLEL. Sequential mode deploys to one Region at a time, limiting the blast radius if a Regional failure occurs, while parallel mode deploys to all target Regions simultaneously. This setting is distinct from account-level concurrency; even in parallel mode, the number of accounts updated at once is still capped by MaxConcurrentCount or MaxConcurrentPercentage.
- ✓
Set the maximum concurrent accounts to control how many accounts are updated simultaneously
Why this is correct
MaxConcurrentAccounts (specified as a count or a percentage of the target accounts) caps how many accounts are updated simultaneously during a StackSet operation. This throttles the deployment speed to avoid overwhelming AWS service limits or creating a large wave of failures at once. It works together with failure tolerance: fewer concurrent accounts means a smaller number of potential failures at any moment, while failure tolerance provides a safety threshold for the overall operation.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.