DOP-C02 SDLC Automation Practice Question
A company uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS instance. The stack creation fails with the error: 'The following resource(s) failed to create: [DBInstance]'. The CloudFormation template includes a parameter for the DB instance class. Which troubleshooting step should be taken FIRST?
⚠ Common exam trap
The trap here is that candidates jump to common RDS prerequisites (like VPC subnets or duplicate identifiers) without first consulting the CloudFormation stack events, which provide the precise failure reason and are the standard diagnostic tool for any stack creation failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the CloudFormation stack events for a detailed status message from the DBInstance resource.
The first step when a CloudFormation stack creation fails is to check the stack events in the CloudFormation console or via the AWS CLI. Each resource creation attempt generates a status message that includes a detailed reason for the failure, such as insufficient capacity, incorrect parameter values, or network configuration issues. For an RDS DBInstance, the event message will provide the specific error (e.g., 'DB instance class not supported in this Availability Zone'), enabling targeted troubleshooting without guesswork.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the stack creation timeout to allow more time for the database to be created.
Why it's wrong here
Increasing the stack creation timeout only adjusts how long CloudFormation waits before declaring the overall stack creation failed; it does not address resource-level validation errors that occur immediately during the DBInstance provisioning. If the database resource returns a CREATE_FAILED status quickly, the problem is almost always an invalid configuration parameter (e.g., unsupported DB instance class, wrong engine, or misconfigured DB subnet group), not a lack of time. Timeout changes would leave the root cause unresolved and would merely delay the same failure.
- ✓
Check the CloudFormation stack events for a detailed status message from the DBInstance resource.
Why this is correct
Checking the CloudFormation stack events is the most direct and authoritative diagnostic step because every resource action logs a status reason that mirrors the exact API error returned by the RDS service. For a DBInstance failure, the event's status message will contain the precise reason—such as an invalid DB instance class, insufficient subnet coverage, or a parameter group mismatch—saving you from guesswork. The events tab also shows the sequence of resource creation, so you can determine whether the failure is isolated to the database or caused by a dependency like a VPC or subnet group that failed earlier.
- ✗
Verify that the VPC has at least two public subnets in different Availability Zones.
Why it's wrong here
Verifying that the VPC has at least two public subnets is incorrect because an Amazon RDS database does not require public subnets; it can be deployed entirely within private subnets. The actual networking requirement is that the DB subnet group contains at least one subnet in two or more Availability Zones, and those subnets can be private. Public subnets with an Internet Gateway are only necessary if you explicitly enable Public Access on the RDS instance, which is neither required by CloudFormation templates nor a common cause of stack creation failure.
- ✗
Use the Amazon RDS console to check if a DB instance with the same identifier already exists.
Why it's wrong here
Using the RDS console to check for an existing DB instance with the same identifier is a possible but indirect and incomplete approach. A duplicate identifier would indeed cause a failure, but that is only one of many potential causes, and CloudFormation stack events already capture the specific error message from the RDS CreateDBInstance call. Furthermore, DB instance identifiers are scoped per AWS account and region, so collisions are less common; even if one exists, you would still need to examine stack events to confirm the failure reason and decide whether to change the identifier or delete the old instance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.