DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to manage its infrastructure. The DevOps team wants to ensure that stack updates do not accidentally delete critical resources like a database. Which CloudFormation stack policy should they apply to protect the database resource?
⚠ Common exam trap
Watch out — candidates often confuse termination protection (which prevents stack deletion) with resource-level protection during updates, leading them to choose option D instead of understanding that stack policies are needed for granular resource safeguards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a stack policy that denies delete actions on the logical resource ID of the database.
A CloudFormation stack policy allows you to define resource-level permissions that prevent specific resources (identified by their logical resource ID) from being updated or deleted during a stack update. By creating a policy that denies delete actions on the database's logical resource ID, the DevOps team ensures that even if the template or parameters change, the database resource cannot be accidentally removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a stack policy that denies delete actions on the logical resource ID of the database.
Why this is correct
A stack policy is a JSON document attached to a CloudFormation stack that controls which update, replacement, or deletion actions are allowed on the stack's resources. By writing a statement that denies the Delete action on the logical resource ID of the database (e.g., the AWS::RDS::DBInstance resource), CloudFormation will refuse to remove or replace that resource during any stack update. This protects the database from being deleted as a side effect of an update, while still permitting other modifications to proceed.
- ✗
Apply an IAM policy that denies cloudformation:DeleteStack on the database.
Why it's wrong here
IAM policies are identity-based permissions that govern what API actions a user, role, or service principal can call, and they cannot target a logical resource inside a CloudFormation stack. The resource ARN in a cloudformation:DeleteStack IAM policy is the stack ARN itself, not an individual resource such as a database. Denying DeleteStack would only prevent the entire stack from being deleted through the DeleteStack API, but it does nothing to stop CloudFormation from deleting and replacing the database during an UpdateStack operation. IAM simply is not the right layer for resource-level protection.
- ✗
Use an S3 bucket policy to deny deletion of the database snapshot.
Why it's wrong here
An S3 bucket policy applies exclusively to Amazon S3 buckets and objects, so it has no bearing on how CloudFormation manages an RDS database or its snapshots. RDS snapshots are stored and administered by the RDS service, not as S3 objects, and a bucket policy cannot intercept CloudFormation's resource-level operations during a stack update. Even if a snapshot were exported to S3, that would be a separate artifact, not the database instance itself. This option is ineffective because it attempts to apply a service-specific policy to an unrelated resource type.
- ✗
Enable termination protection on the CloudFormation stack.
Why it's wrong here
Termination protection is a CloudFormation stack-level attribute that prevents the entire stack from being deleted using the DeleteStack API, but it does not govern the deletion or replacement of individual resources during a stack update. When an update requires a resource replacement, CloudFormation deletes the old resource as part of the UpdateStack flow, and termination protection will not block that action. The stack itself remains intact, yet the database can still be lost. This is why resource-level protection, such as a stack policy with a Deny on Delete, is necessary for that scenario.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.