Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails because the new instances cannot connect to the database. The previous deployment succeeded. The DevOps engineer checks the CodeDeploy deployment configuration and finds that the deployment uses the 'CodeDeployDefault.AllAtOnce' configuration. What is the MOST likely cause of the failure?

⚠ Common exam trap

Many exam-takers assume the failure is due to a misconfiguration (like security groups or health checks) rather than recognizing that the deployment strategy itself—replacing all instances at once—amplifies the impact of any application-level incompatibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The deployment replaced all instances at once, causing a temporary loss of connectivity if the new application version has incompatible changes.

The 'CodeDeployDefault.AllAtOnce' deployment configuration causes CodeDeploy to attempt to deploy the new application revision to all instances in the Auto Scaling group simultaneously. If the new application version contains incompatible changes—such as a database schema mismatch, altered connection strings, or missing environment variables—all instances will fail at the same time, resulting in a complete loss of connectivity to the database. This contrasts with a rolling or canary deployment, which would limit the blast radius by updating only a subset of instances at a time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The load balancer health check is misconfigured, causing new instances to be deregistered.

    Why it's wrong here

    A misconfigured load balancer health check could cause the target group to mark new instances as unhealthy and deregister them, but that scenario would only remove instances from traffic rotation; it would not interfere with the instances' ability to establish outbound connections to a database. The reported symptom is a transient loss of database connectivity during deployment, which is unrelated to health check verdicts. CodeDeploy also never changes the target group's health check settings; it simply reads the existing health status to decide whether a deployment succeeded.

  • ✗

    The deployment group is not configured to handle traffic routing, causing a routing loop.

    Why it's wrong here

    AllAtOnce deployments do not use any staged traffic routing; CodeDeploy stops every instance in the deployment group, installs the new revision, and restarts them without any shift of user traffic between old and new environments. A routing loop is a network-level packet forwarding issue that would cause traffic to bounce between routers, not a temporary application-to-database connectivity problem. Therefore, a missing traffic routing configuration is irrelevant because AllAtOnce deployments by design have no routing phase, and CodeDeploy does not manage network routing tables.

  • ✗

    The security group for the Auto Scaling group was updated during deployment, blocking database access.

    Why it's wrong here

    CodeDeploy does not modify security groups, network ACLs, or any other VPC networking component during the deployment process; its agent only transfers the application revision, runs scripts, and executes lifecycle hooks on the EC2 instances. Even if a security group update were made manually or via a separate automation, that change would be persistent, not a temporary outage that resolves after the deployment completes. Furthermore, blocking the database port via a security group would affect all instances simultaneously for as long as the rule exists, not just for the deployment window, so this explanation cannot account for a transient loss of connectivity.

  • ✓

    The deployment replaced all instances at once, causing a temporary loss of connectivity if the new application version has incompatible changes.

    Why this is correct

    With an AllAtOnce deployment strategy, CodeDeploy stops every current instance at the same time, deploys the new application revision to each, and then restarts them; this creates a zero-capacity window where no instance is serving traffic. If the new revision contains incompatible changes—such as expecting a new database schema, missing environment variables, or a different API version—the restarted instances may fail to connect to the database, leaving the entire application unavailable until the issues are resolved. This is the classic failure mode of AllAtOnce deployments: every instance fails together, so a single backward-incompatibility causes a full, fleet-wide outage rather than a partial degradation.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.