Courseiva

DOP-C02 Incident and Event Response Practice Question

A company uses AWS CloudFormation to manage infrastructure. During an incident, a stack update fails with the error 'The following resource(s) failed to create: [AWS::RDS::DBInstance]'. Which AWS service should the engineer use to view detailed error messages for the failed resource creation?

⚠ Common exam trap

DOP-C02 often tests whether candidates conflate CloudTrail (API audit) with CloudFormation Events (resource-level deployment diagnostics), leading them to pick CloudTrail when the question asks for the specific failure reason.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudFormation console Events tab

The CloudFormation console's Events tab shows the chronological sequence of stack events, including the specific status reason for each resource failure. When a resource like AWS::RDS::DBInstance fails to create, the Events tab displays the underlying error message returned by the RDS API (e.g., invalid parameter, insufficient privileges, or subnet issues). This is the fastest and most direct way to diagnose the failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config timeline

    Why it's wrong here

    The AWS Config timeline tracks configuration state changes for individual AWS resources over time, recording what changed and when. It is useful for auditing resource drift or historical config, but it does not capture error messages from CloudFormation stack operations, such as the failure reason for a resource creation. For a failed stack deployment, you need the resource-specific status reason, which Config does not provide.

  • ✓

    AWS CloudFormation console Events tab

    Why this is correct

    The CloudFormation console Events tab lists every operation performed on a stack in chronological order, one per resource action, including statuses like CREATE_FAILED and UPDATE_FAILED. For each failed event, the Status Reason field contains the exact error message returned by the underlying service, such as an IAM permission issue or a missing S3 bucket. This is the authoritative source for diagnosing stack deployment problems.

  • ✗

    AWS Service Catalog

    Why it's wrong here

    AWS Service Catalog is a catalog service that lets organizations create, manage, and deploy approved IT services, often built on CloudFormation templates, but it is a governance and provisioning tool, not a diagnostic tool. When a stack fails, Service Catalog does not expose the CloudFormation resource-level error events or status reasons required for troubleshooting. It also cannot be used to inspect a specific stack's deployment history beyond the product's provisioning status.

  • ✗

    AWS CloudTrail event history

    Why it's wrong here

    AWS CloudTrail event history records API calls made by IAM users or services to AWS, including CloudFormation's CreateStack, UpdateStack, and DeleteStack calls, along with the requesting principal and response elements. However, it captures the API request/response level, not the intra-stack resource failures that occur during a template's execution; the failed resource's status reason is not present in the CloudTrail log event. Thus, CloudTrail is useful for auditing who initiated a stack change, not for identifying why a specific resource failed.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.