Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation to manage infrastructure. The DevOps team wants to implement a change management process where all stack updates must be reviewed before execution. Which AWS feature should be used?

⚠ Common exam trap

A common mix-up: candidates confuse drift detection (which detects post-update configuration drift) with the ability to preview proposed changes, or they mistakenly think stack policies can gate the update itself rather than just protecting specific resources during an update.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change Sets

Change Sets allow you to preview how proposed changes to a CloudFormation stack will impact your running resources before you execute them. This enables a review-and-approval workflow, making it the correct choice for implementing a change management process where all stack updates must be reviewed before execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Drift detection

    Why it's wrong here

    Drift detection is a reactive auditing feature that compares the template-defined desired state to the actual live configuration of resources. It reports only after changes have already occurred—usually from out-of-band manual modifications—and cannot preview, approve, or sequence an update. Since it does not affect how CloudFormation executes a stack update, it provides no change review mechanism.

  • ✓

    Change Sets

    Why this is correct

    A change set is a read-only summary of the modifications CloudFormation will perform if you execute it, including resource additions, removals, and replacements with details such as `Replacement` and `RequiresRecreation`. You create a change set, inspect its proposed actions—even using `--changeset` filtering or the console UI—and only then choose to execute it, which gives you a controlled, auditable review gate before any infrastructure is altered.

  • ✗

    StackSets

    Why it's wrong here

    StackSets extend CloudFormation to create, update, or delete stack instances in multiple target accounts and regions from a single stack set, with automatic drift detection and granular permission control via `self-managed` or `service-managed` permissions. They are designed for governance and consistent multi-account deployments, not for generating a preview of changes to an existing stack. A StackSet operation applies updates directly after you invoke it; it does not include a separate review step of the kind that a change set provides.

  • ✗

    Stack policies

    Why it's wrong here

    Stack policies are explicit permission documents attached to a stack that restrict what update actions are allowed on specified resources, protecting critical components from accidental destruction (for example, preventing update of an `AWS::S3::Bucket`). They do not produce a list of pending modifications, nor do they allow you to review and selectively execute an update. They are a preventive control, whereas a change set is an informational and approval-oriented control.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.