DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to manage its infrastructure. The DevOps team notices that stack updates sometimes fail because of resource conflicts. The team wants to prevent concurrent updates to the same stack. What should they do?
⚠ Common exam trap
The trap here is that candidates overthink the problem and assume they need to implement custom concurrency controls (like IAM policies or SCPs), when in fact CloudFormation already handles this natively, making the 'no action needed' answer the correct one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No action needed; CloudFormation already prevents concurrent stack updates
AWS CloudFormation inherently prevents concurrent updates to the same stack. When an update operation is initiated, CloudFormation places a lock on the stack, rejecting any subsequent update requests until the current operation completes. This behavior is built into the service and requires no additional configuration, making option C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an AWS Organizations service control policy to restrict updates
Why it's wrong here
Service control policies (SCPs) operate at the AWS Organizations boundary and can deny CloudFormation UpdateStack actions for all principals in an account. However, an SCP is a coarse-grained preventive guardrail for governance, not a concurrency-control mechanism; it cannot distinguish between an idle stack and one mid-update, and it would block legitimate updates entirely. Because CloudFormation already rejects a second mutating request while a stack update is running, adding an SCP would only introduce operational friction without improving atomicity or serialization.
- ✗
Create an IAM policy that denies cloudformation:UpdateStack if a stack update is in progress
Why it's wrong here
This approach is unimplementable because IAM policies evaluate the request context and CloudFormation does not expose the stack's update status as an IAM condition key. Conditions such as cloudformation:ResourceTag are available, but there is no condition like 'UpdateInProgress' to attach to a Deny statement. A blanket Deny on cloudformation:UpdateStack would stop all stack updates, not merely concurrent ones, and would fail to solve the stated problem—whereas the service's built-in lock already rejects overlapping update calls.
- ✓
No action needed; CloudFormation already prevents concurrent stack updates
Why this is correct
No action is required because the CloudFormation service applies a mutual-exclusion lock to each stack: from the moment an UpdateStack call is accepted until the update, rollback, or clean-up finishes, any subsequent UpdateStack, DeleteStack, or ExecuteChangeSet operation on the same stack is rejected with a ValidationError such as 'Stack is currently in an update state'. This built-in serialization prevents concurrent modifications and preserves stack consistency without any downstream code, IAM policy, or auxiliary lock. Therefore, the design is already safe, and adding extra mechanisms is redundant.
- ✗
Enable CloudTrail to log all stack update attempts and manually review
Why it's wrong here
CloudTrail data events can record every UpdateStack API call and, after the fact, a reviewer could notice attempted overlapping updates—but logging is purely detective and has no effect on whether the second request actually executes. By the time a human reviews the trail, the denied or failed attempt has already been processed by CloudFormation's concurrency guard, and the log would only show that the service rejected it. Relying on CloudTrail and manual review adds operational overhead and response latency instead of leveraging the automatic prevention already in place.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.