DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS Elastic Beanstalk to deploy a web application. The environment is running behind an Application Load Balancer. The DevOps team notices that during deployments, the new application version fails health checks and the deployment rolls back. The team wants to reduce deployment time while maintaining safety. Which configuration change should the engineer recommend?
⚠ Common exam trap
The trap is assuming that increasing batch size or instance count accelerates a rolling update, but the real issue is failed health checks during the rolling update causing rollbacks. Immutable deployments bypass this by launching and validating a completely new set of instances before switching traffic, rather than relying on modifications to the existing fleet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the deployment policy to immutable.
The immutable deployment policy in AWS Elastic Beanstalk creates a new Auto Scaling group with fresh instances running the new application version, performs health checks, and only then swaps the environment's target group to route traffic to the new fleet. This avoids the rolling update's problem of health check failures on existing instances (which trigger a rollback) and ensures the entire new environment is validated before any traffic is shifted. While immutable deployments can take longer than a successful rolling update because they provision a full new fleet, they reduce overall deployment time in this scenario by preventing repeated failed deployments and rollbacks, and they maintain safety by not exposing partially updated instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the number of EC2 instances in the environment.
Why it's wrong here
Increasing the number of EC2 instances only adds capacity; it does not alter the deployment method. During a rolling or all-at-once update, every instance is still replaced sequentially or simultaneously, so a faulty new version can impact the entire fleet regardless of instance count. The immutable policy, not instance count, provides the required safe deployment by launching a fresh environment before switching traffic.
- ✗
Use the all-at-once deployment policy.
Why it's wrong here
The all-at-once deployment policy terminates all existing instances and launches new ones in a single step. It performs no health checks before serving traffic, so if the new application version fails, the entire environment becomes unavailable. Immutable deployments avoid this by validating the new fleet's health before any traffic is shifted, whereas all-at-once exposes users to immediate risk.
- ✓
Change the deployment policy to immutable.
Why this is correct
Changing the deployment policy to immutable launches a fully new Auto Scaling group with the new application version while the old group continues serving traffic. Once the new instances pass health checks, Elastic Beanstalk swaps the environment's capacity to the new group, providing both safety and minimal downtime. This is the correct choice because it verifies the deployment before cutting over, unlike rolling or all-at-once strategies that update existing instances in place.
- ✗
Increase the rolling update batch size to 100%.
Why it's wrong here
Setting the rolling update batch size to 100% causes all instances to be replaced at once, with no opportunity for health checks between batches. This effectively replicates the risk of an all-at-once deployment, meaning a faulty version will corrupt the entire environment simultaneously. Immutable deployments are preferable because they isolate the new version in a separate fleet and only route traffic after successful health verification.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.