DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS CloudFormation to manage its infrastructure. The DevOps team needs to deploy a stack that includes a Lambda function and an S3 bucket. The Lambda function's code is stored in the S3 bucket. How can the team ensure that the Lambda function is created after the S3 bucket and the code is uploaded?
⚠ Common exam trap
Candidates often assume CloudFormation automatically orders resources based on template order or implicit references like Fn::GetAtt, but it does not infer dependencies from code uploads or resource definition order, so explicit DependsOn is required for non-attribute-based dependencies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the DependsOn attribute on the Lambda function to depend on the S3 bucket.
The DependsOn attribute explicitly instructs CloudFormation to create the S3 bucket before the Lambda function. Even though CloudFormation automatically determines resource dependencies for certain intrinsic functions, it does not infer dependencies based on code uploads. Using DependsOn ensures the bucket exists and the code is uploaded before the Lambda function is created, preventing a deployment failure when the Lambda references code that is not yet available.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Upload the code to the S3 bucket before creating the stack.
Why it's wrong here
Uploading code to an S3 bucket before creating the stack is not viable when that bucket is defined in the same CloudFormation template, since the bucket does not yet exist at that point and the upload would require a manual, out-of-band step outside the IaC workflow. Even if the bucket already pre-exists, this action does not attach any dependency edge to the Lambda function in CloudFormation's resource graph, so it cannot enforce that the bucket is fully configured before the function is provisioned. The manual step also breaks automation and repeatability, which CloudFormation is meant to provide.
- ✗
Use the Fn::GetAtt intrinsic function to retrieve the bucket name.
Why it's wrong here
Fn::GetAtt is an intrinsic function that retrieves a specific attribute (such as the bucket name) from a resource after it has been created, but invoking it does not, by itself, declare a dependency unless it appears in a resource property that CloudFormation is able to trace. If the returned value is used only in outputs or other non-resource contexts, CloudFormation will not treat it as a dependency edge, so it provides no guarantee that the S3 bucket has finished creation before the Lambda function starts. Only a direct reference in the Lambda function's properties or an explicit DependsOn can enforce the ordering.
- ✗
Define the S3 bucket resource before the Lambda function resource in the template.
Why it's wrong here
The physical order in which resources are listed in a CloudFormation template is only cosmetic and does not drive the actual creation sequence. CloudFormation analyzes the dependency graph from intrinsic references like Ref and Fn::GetAtt, plus explicit DependsOn attributes, and then creates resources according to that graph's topological order, allowing independent resources to be created in parallel. Therefore, simply placing the S3 bucket before the Lambda function provides no guarantee that the bucket will exist when the function is provisioned; without a dependency declaration, CloudFormation may even create the Lambda function first.
- ✓
Use the DependsOn attribute on the Lambda function to depend on the S3 bucket.
Why this is correct
The DependsOn attribute explicitly declares a dependency edge from the Lambda function back to the S3 bucket, forcing CloudFormation to wait until the bucket resource has reached CREATE_COMPLETE before it starts provisioning the Lambda function. This is the definitive way to guarantee creation order, especially when the function needs the bucket to exist for side effects such as populating an environment variable, writing to the bucket, or associating permissions, and no implicit dependency exists in the template. Unlike implicit references, DependsOn works even if the bucket is not directly referenced in any property of the Lambda function, making it the correct answer.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.