DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to deploy infrastructure. They want to implement a change management process that requires approval before any stack update is executed. Which TWO approaches can achieve this? (Choose TWO.)
⚠ Common exam trap
It's easy for candidates to confuse Change Sets (which allow review but not approval enforcement) with a true approval workflow, or they incorrectly assume StackSets or Service Catalog can be repurposed for stack update approvals.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CodePipeline with a manual approval stage before the CloudFormation deployment action.
AWS CodePipeline can include a manual approval action that pauses the pipeline until an authorized user approves the change, after which the CloudFormation deployment action executes the stack update. This enforces a formal approval gate before any infrastructure change is applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS CodePipeline with a manual approval stage before the CloudFormation deployment action.
Why this is correct
CodePipeline's manual approval action is a first-class gate that pauses execution between stages; a configured principal (often a manager or lead) must explicitly approve via console, CLI, or API before the pipeline proceeds to the CloudFormation deployment stage. This enforces separation of duties, because the engineer who initiated the pipeline cannot be the sole approver unless policies allow it. It works natively with the pipeline state machine and keeps an audit trail of who approved and when.
- ✗
Use CloudFormation StackSets with approval tokens.
Why it's wrong here
StackSets are designed to deploy and update identical CloudFormation templates across multiple AWS accounts and Regions, not to gate an individual stack update in a single workflow. They have no concept of approval tokens; operation execution is authorized through standard IAM roles and optional SCPs, with no manual-approval hook in the StackSets execution model. Therefore, StackSets cannot provide the required pre-update human sign-off.
- ✗
Use CloudFormation Change Sets and require a separate user to execute them.
Why it's wrong here
Change Sets give a read-only preview of the resources that will be added, modified, or deleted before you execute the change set, but CloudFormation does not require—or even track—who executes it. Any IAM principal with the cloudformation:ExecuteChangeSet permission can run it, and there is no native mechanism to mandate that the executing user differ from the change set creator. To enforce a 'separate user' you would need to augment Change Sets with a custom workflow, such as SCPs, Lambda-backed policy checks, or an external approval step.
- ✗
Use AWS Service Catalog to manage CloudFormation templates and require approval for product launches.
Why it's wrong here
Service Catalog is aimed at end-user self-service provisioning of approved CloudFormation products, typically with an approval workflow for portfolio launches. However, it does not manage updates to an existing stack that was created outside Service Catalog, nor does it gate the execution of an arbitrary CloudFormation template in a CI/CD pipeline. Although you could wrap a template as a product, Service Catalog cannot act as an approval stop for an ongoing stack update triggered by a infrastructure deployment.
- ✓
Implement a custom AWS Lambda function that checks a ticketing system before allowing the update to proceed.
Why this is correct
A custom Lambda function can be inserted as a pipeline action—for example, as a pre-deployment step in CodePipeline or as part of a Step Functions workflow—to call an external ticketing system's API and verify that a valid change ticket exists and is approved. If the ticket is missing or not yet approved, the function can throw an exception or fail the action, halting the deployment. This approach provides complete flexibility to align with an organization's ITSM process, though it requires additional code, IAM permissions, and maintenance compared to a native approval action.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.