Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation to manage infrastructure. The team wants to ensure that all stack updates are reviewed and approved before execution. Which mechanism should the team implement?

⚠ Common exam trap

Many candidates confuse stack policies (which control resource-level permissions) with change sets (which provide a preview of changes), or they mistakenly think termination protection or drift detection can gate updates, when neither is designed for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudFormation change sets to review the proposed changes before executing the update.

AWS CloudFormation change sets allow you to preview how proposed changes to a stack will be applied before you execute them. This includes a summary of additions, modifications, and deletions of resources, enabling you to review and approve the changes in a controlled manner. By generating a change set, the team can ensure that no update is executed without prior review and approval, meeting the requirement for a gated deployment process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a stack policy that denies all updates unless approved.

    Why it's wrong here

    A stack policy is a resource-level IAM policy that can explicitly deny update, replace, or delete actions on specified logical resources during a CloudFormation update. However, it only enforces whether an operation is permitted—it does not surface the details of what the template change would do, nor provide an approval workflow to evaluate impact. Requiring an approve step outside CloudFormation without using change sets still leaves you blind to the exact resource modifications before the update is attempted.

  • ✗

    Use AWS CloudFormation drift detection to identify changes before updating.

    Why it's wrong here

    Drift detection compares the current live configuration of a stack's resources against the template and parameters CloudFormation last deployed, revealing manual modifications made outside of stack operations. It is backward-looking: it reports whether the existing infrastructure has diverged from the intended state, not what changes a proposed new template would introduce. Therefore, running drift detection before an update gives no preview of additions, replacements, or deletions that the new version would cause, so it cannot serve as a review mechanism for the update itself.

  • ✗

    Enable termination protection on the stack to prevent accidental updates.

    Why it's wrong here

    Termination protection is an attribute on the stack that prevents the DeleteStack API call from succeeding, thereby guarding against accidental removal of the entire stack and all of its managed resources. It has no bearing on update operations—you can still execute Updates or change sets that disrupt or replace running resources while termination protection is enabled. Since the risk being mitigated is deletion, not modification, this setting does nothing to help review or approve the content of proposed infrastructure changes.

  • ✓

    Use AWS CloudFormation change sets to review the proposed changes before executing the update.

    Why this is correct

    A change set is a read-only summary of the exact modifications CloudFormation will make to the stack when you execute it, including resource type add/remove/replace and whether the change is dynamically applied or requires no interruption. You can create and inspect multiple change sets from different template versions without touching live infrastructure, then deliberately execute the approved one—only execution applies the update. This gives you the review-before-apply gate that the requirement asks for, as the change set is the proposed changes themselves rather than a policy or detection signal.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.