Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CodeDeploy to deploy applications to an Auto Scaling group. During a deployment, the deployment fails because the target instances are not passing the health checks. The DevOps engineer notices that the CodeDeploy agent logs show 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' Which step should the engineer take to diagnose the issue?

⚠ Common exam trap

The trap here is that candidates often jump to infrastructure-level fixes (like scaling or monitoring) when the error message clearly points to per-instance script failures, which require examining the CodeDeploy agent logs on a failed instance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the CodeDeploy deployment logs on a failed instance to identify script errors.

The error message indicates that individual instances failed deployment, and the CodeDeploy agent logs on a failed instance contain detailed script output (e.g., AppSpec hooks like BeforeInstall, AfterInstall, ApplicationStart) that reveal the root cause, such as a missing dependency or incorrect file path. Reviewing these logs directly identifies script errors, which is the most targeted diagnostic step before considering infrastructure changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the size of the Auto Scaling group to ensure more instances are available.

    Why it's wrong here

    Increasing the Auto Scaling group size adds instances, but a CodeDeploy deployment reaches all instances in the fleet; the failing lifecycle script will simply execute and fail on every instance, possibly triggering a rollback or an unhealthy instance replacement. This only multiplies the scope of the failure and consumes additional resources without correcting the syntax, permissions, or dependencies that caused the script to exit non-zero. The root cause remains on the instance itself, so capacity changes are irrelevant to the diagnosis.

  • ✓

    Review the CodeDeploy deployment logs on a failed instance to identify script errors.

    Why this is correct

    The CodeDeploy agent on the failed instance writes execution logs that include the full stdout and stderr for every lifecycle event hook, such as BeforeInstall and ApplicationStop. These logs are available at /var/log/aws/codedeploy-agent/codedeploy-agent.log and under /opt/codedeploy-agent/deployment-root/deployment-logs, and they reveal the exact script command that failed and the error message. Reviewing these logs is the only way to directly observe the script's runtime behavior, making it the correct first step in troubleshooting.

  • ✗

    Create a CloudWatch alarm to monitor the deployment health.

    Why it's wrong here

    A CloudWatch alarm can monitor CodeDeploy metrics like FailedDeployments or track instance health, but the alarm only fires when a pre-defined threshold is breached; it does not contain or surface the script's error output. Even if you set an alarm, you still have to manually inspect instance logs to learn why the script failed, meaning the alarm adds latency and notification value but zero diagnostic value. It is a reactive monitoring tool, not a root-cause analysis mechanism for lifecycle hook failures.

  • ✗

    Check AWS CloudTrail logs for the CodeDeploy API calls to see if permissions are missing.

    Why it's wrong here

    CloudTrail records control-plane API calls such as CreateDeployment, GetDeployment, or permission failures from IAM policies, but lifecycle event scripts execute within the instance's operating system and are outside CloudTrail's visibility. If missing IAM permissions caused a script to fail, you would often see an API error like AccessDenied in CloudTrail, but script errors like a missing file or a syntax mistake produce no CloudTrail event. Since this question asks about identifying script errors, CloudTrail is the wrong place to look.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.