DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS DB instance and an EC2 instance that connects to it. The DB instance has a deletion policy of 'Retain'. The stack fails to delete because the DB instance is retained and still exists. Which TWO actions would allow the stack to be deleted successfully? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse 'Retain' deletion policy with 'DeletionProtection' or assume that termination protection on EC2 instances is relevant, when in fact the core issue is that the retained resource must be either manually removed or its policy changed to allow CloudFormation to delete it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually delete the DB instance using the RDS console.
Manually deleting the retained DB instance removes the resource that is blocking the stack deletion. CloudFormation cannot delete a stack that contains a resource with a 'Retain' deletion policy until that resource is manually removed, as the stack expects the resource to no longer exist for the deletion to complete.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the AWS CLI to force delete the stack with the --force option.
Why it's wrong here
There is no --force option for the AWS CLI delete-stack command. Running `aws cloudformation delete-stack` accepts only parameters such as --stack-name, --role-arn, --client-request-token, and --retain-resources; a force flag does not exist. When stack deletion fails because a resource cannot be removed, CloudFormation enters DELETE_FAILED state, and you must resolve the underlying resource issue or use --retain-resources to explicitly skip that resource rather than attempting a fictional forced deletion.
- ✓
Manually delete the DB instance using the RDS console.
Why this is correct
Manually deleting the RDS DB instance from the RDS console removes the physical database object from the account, circumventing CloudFormation's inability to delete it automatically. This is a valid operational workaround when the stack is stuck in DELETE_FAILED because the DB instance is protected by RDS deletion protection or has a DeletionPolicy of Retain. Once the resource is gone, a subsequent stack delete operation will succeed because CloudFormation no longer attempts to delete that DB instance.
- ✗
Disable termination protection on the EC2 instance.
Why it's wrong here
Disabling EC2 termination protection is irrelevant because the problem is specifically about an RDS DB instance, not an EC2 instance. Termination protection only prevents an EC2 instance from being accidentally terminated via AWS APIs or the console; it has no effect on RDS resources or CloudFormation's ability to delete a database stack. Addressing EC2 settings does not clear the RDS deletion roadblock causing the stack deletion failure.
- ✓
Change the deletion policy of the DB instance to 'Delete' and then update the stack before deleting.
Why this is correct
Changing the DB instance's DeletionPolicy from Retain to Delete and then updating the stack propagates the new policy to the resource before stack deletion. After the update, CloudFormation's template explicitly instructs the service to delete the DB instance when the stack is deleted. This is the correct CloudFormation-native approach because it aligns the stack's desired state with the teardown operation, allowing the resource to be removed automatically.
- ✗
Modify the DB instance to allow deletion by setting DeletionProtection to false.
Why it's wrong here
Setting RDS DeletionProtection to false alone is insufficient when the CloudFormation stack has a DeletionPolicy of Retain. RDS deletion protection is an AWS data-safety guard, but CloudFormation's DeletionPolicy governs whether the stack will even attempt to delete the resource during stack deletion. If DeletionPolicy is Retain, CloudFormation will leave the DB instance intact regardless of whether deletion protection is disabled; you must also change the DeletionPolicy to Delete or manually remove the resource.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.