Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team notices that stack updates sometimes fail because of resource conflicts. The team wants to prevent concurrent updates to the same stack. What should they do?

⚠ Common exam trap

The trap here is that candidates overthink the problem and assume they need to implement custom concurrency controls (like IAM policies or SCPs), when in fact CloudFormation already handles this natively, making the 'no action needed' answer the correct one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No action needed; CloudFormation already prevents concurrent stack updates

AWS CloudFormation inherently prevents concurrent updates to the same stack. When an update operation is initiated, CloudFormation places a lock on the stack, rejecting any subsequent update requests until the current operation completes. This behavior is built into the service and requires no additional configuration, making option C correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Organizations service control policy to restrict updates

    Why it's wrong here

    Service control policies (SCPs) operate at the AWS Organizations boundary and can deny CloudFormation UpdateStack actions for all principals in an account. However, an SCP is a coarse-grained preventive guardrail for governance, not a concurrency-control mechanism; it cannot distinguish between an idle stack and one mid-update, and it would block legitimate updates entirely. Because CloudFormation already rejects a second mutating request while a stack update is running, adding an SCP would only introduce operational friction without improving atomicity or serialization.

  • ✗

    Create an IAM policy that denies cloudformation:UpdateStack if a stack update is in progress

    Why it's wrong here

    This approach is unimplementable because IAM policies evaluate the request context and CloudFormation does not expose the stack's update status as an IAM condition key. Conditions such as cloudformation:ResourceTag are available, but there is no condition like 'UpdateInProgress' to attach to a Deny statement. A blanket Deny on cloudformation:UpdateStack would stop all stack updates, not merely concurrent ones, and would fail to solve the stated problem—whereas the service's built-in lock already rejects overlapping update calls.

  • ✓

    No action needed; CloudFormation already prevents concurrent stack updates

    Why this is correct

    No action is required because the CloudFormation service applies a mutual-exclusion lock to each stack: from the moment an UpdateStack call is accepted until the update, rollback, or clean-up finishes, any subsequent UpdateStack, DeleteStack, or ExecuteChangeSet operation on the same stack is rejected with a ValidationError such as 'Stack is currently in an update state'. This built-in serialization prevents concurrent modifications and preserves stack consistency without any downstream code, IAM policy, or auxiliary lock. Therefore, the design is already safe, and adding extra mechanisms is redundant.

  • ✗

    Enable CloudTrail to log all stack update attempts and manually review

    Why it's wrong here

    CloudTrail data events can record every UpdateStack API call and, after the fact, a reviewer could notice attempted overlapping updates—but logging is purely detective and has no effect on whether the second request actually executes. By the time a human reviews the trail, the denied or failed attempt has already been processed by CloudFormation's concurrency guard, and the log would only show that the service rejected it. Relying on CloudTrail and manual review adds operational overhead and response latency instead of leveraging the automatic prevention already in place.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.