DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to deploy a multi-tier application. The template includes a parameter for the instance type of EC2 instances. The DevOps team wants to restrict the allowed values to a specific set of instance types. Which CloudFormation section should be used?
⚠ Common exam trap
Test-takers frequently confuse Mappings (which are static lookups) with parameter constraints, thinking they can restrict input values via a mapping, but Mappings only retrieve pre-defined data and do not enforce input validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Parameters with AllowedValues
The Parameters section in AWS CloudFormation allows you to define input values that can be supplied at stack creation or update time. By specifying an AllowedValues constraint on a parameter, you restrict the user to select only from a predefined list of instance types, which enforces compliance and prevents misconfiguration. This is the correct mechanism for limiting instance type choices in a CloudFormation template.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outputs
Why it's wrong here
Outputs are declarations that expose information about a completed CloudFormation stack, such as a load balancer DNS name or database endpoint, for review in the console or for use by other stacks via cross-stack references. They do not influence resource creation, validate user input, or constrain the set of allowed deployment choices—they simply return values after the stack operation completes. Therefore, Outputs cannot be used to restrict which environment or configuration a user selects for a multi-tier application.
- ✓
Parameters with AllowedValues
Why this is correct
Parameters with AllowedValues is the correct mechanism because it defines an input variable whose acceptable values are explicitly enumerated at template authoring time. When the stack is created or updated, CloudFormation validates any supplied value against that list and rejects the operation if the value is not present. This provides a controlled menu of environment-specific options (e.g., Dev, Staging, Prod) or instance types, ensuring the multi-tier app is deployed with a valid, pre-approved configuration.
- ✗
Conditions
Why it's wrong here
Conditions govern whether a particular resource, nested stack, or other template section is created based on the evaluation of logical expressions involving parameters, mappings, or other conditions. They are not input validators; they do not constrain what values a parameter can hold. For instance, a condition might create a production-only resource when the environment parameter equals 'Prod', but it cannot prevent a user from passing an unsupported value for that parameter in the first place.
- ✗
Mappings
Why it's wrong here
Mappings are static lookup tables that associate a key with a set of values, commonly used to simplify template logic by selecting region- or AZ-specific attributes like AMI IDs or instance sizes. While parameter values can be used as keys in a mapping via Fn::FindInMap, mappings themselves do not validate or restrict parameter input—any arbitrary value can still be passed for a parameter unless AllowedValues is also specified. Thus, on their own, Mappings cannot enforce a finite list of allowable deployments.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.