Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation to deploy infrastructure across multiple accounts. They want to reuse a set of resource definitions for a standard VPC configuration. Which approach minimizes duplication and maintains centralized control?

⚠ Common exam trap

A common mix-up: candidates confuse CloudFormation macros with modules, thinking macros can encapsulate reusable resources, but macros only transform template code at deploy time and do not provide a reusable resource definition mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CloudFormation module for the VPC resources and reference it in each stack.

CloudFormation modules allow you to encapsulate a set of resource definitions into a reusable component that can be referenced across multiple stacks. This approach minimizes duplication because the module is defined once in a central registry (e.g., the CloudFormation public or private module registry) and each stack simply includes a `Module` declaration. It also maintains centralized control because updates to the module are automatically propagated to all stacks that reference it, without requiring manual template copying or stack updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CloudFormation module for the VPC resources and reference it in each stack.

    Why this is correct

    CloudFormation modules encapsulate a group of resources—such as a VPC with subnets, route tables, and gateways—so they can be referenced as a single reusable component in multiple stacks. Modules support parameters, outputs, and semantic versions, enabling centralized management and consistent configuration across accounts and regions without duplicating resource definitions. When a module is included in a stack, its resources become part of that stack's resource graph, so you can access their outputs directly in the same template, simplifying stack-level operations like changes and rollbacks.

  • ✗

    Define the VPC resources in a CloudFormation macro and call the macro from each stack.

    Why it's wrong here

    CloudFormation macros are template-processing functions that perform operations on the raw template text before it is deployed, such as string substitution, looping, or conditional modifications via AWS Lambda. They do not package or encapsulate resources; you would still need to author the entire VPC definition inside the macro code and invoke it via Fn::Transform, which is cumbersome and untransparent for reuse. Macros alter template syntax dynamically, but they don't give you a versioned, composable resource unit that can be simply referenced like a module, so they are the wrong tool for sharing infrastructure patterns.

  • ✗

    Publish the VPC template in AWS Service Catalog and have each account provision from it.

    Why it's wrong here

    AWS Service Catalog is a governance service that lets organizations publish curated products (CloudFormation templates) for end users to provision independently. It is designed for self-service provisioning and approval workflows, not for embedding a resource segment into another stack's resource graph. If you use Service Catalog, each account would launch a separate VPC stack rather than reusing a VPC as a component inside an existing stack, causing fragmented stack boundaries and making it harder to manage cross-stack dependencies or shared outputs.

  • ✗

    Use nested stacks by creating a separate template for the VPC and including it in each account's stack.

    Why it's wrong here

    Nested stacks do allow you to create a separate template for the VPC and include it via the AWS::CloudFormation::Stack resource, but the child template must be stored in an S3 bucket, and the nested stack manages its own lifecycle and events. This adds operational overhead: every update of the parent stack triggers a nested stack update, and you must handle cross-stack references and rollback behavior separately. CloudFormation modules, by contrast, are first-class reusable resource components included directly in the parent template, providing simpler syntax, native resource-level integration, and versioning without the need for separate stack management.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.