DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS Elastic Beanstalk with a custom platform. They need to update the platform version to include a new security patch. Which approach should be used to create a new custom platform version?
⚠ Common exam trap
Many exam-takers assume they can directly modify an existing platform version or use manual EC2 operations, but Elastic Beanstalk custom platforms require a formal versioning process through the platform definition file and the `create-platform-version` API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new platform version using the aws elasticbeanstalk create-platform-version command with an updated platform definition file.
AWS Elastic Beanstalk custom platforms are defined using a platform definition file (a YAML or JSON file that specifies the AMI, Chef recipes, and other configuration). To create a new platform version with an updated security patch, you must update this platform definition file (e.g., to reference a new base AMI with the patch) and then run the `aws elasticbeanstalk create-platform-version` CLI command. This command packages the definition file and uploads it to Elastic Beanstalk, which then builds and registers the new platform version. The other options either bypass the custom platform framework or are not supported operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Elastic Beanstalk CLI to rebuild the platform with the new AMI.
Why it's wrong here
The Elastic Beanstalk CLI (EB CLI) is a client-side tool for deploying and managing application environments; it has no capability to rebuild or mutate the underlying custom platform itself. Custom platform operations, such as creating or updating a platform version, require the AWS SDK or CLI commands like create-platform-version, not the EB CLI. Therefore this option is invalid because it misidentifies the tool responsible for custom platform lifecycle management.
- ✗
Launch a new EC2 instance, apply the patch, and create an AMI, then update the platform version.
Why it's wrong here
Platform versions are immutable artifacts; after a custom platform version is created, it cannot be altered or updated in place. Even if you build a patched AMI from a running EC2 instance, Elastic Beanstalk provides no mechanism to update an existing platform version to point to that new AMI—the only valid approach is to create a brand-new platform version from a modified platform definition. Thus, the proposed sequence fails because it assumes an update operation exists that simply does not.
- ✗
Modify the existing platform version's AMI ID using the Elastic Beanstalk console.
Why it's wrong here
The Elastic Beanstalk console displays platform versions but offers no editing capability for their underlying AMI IDs or any other configuration; platform versions are immutable once published. Attempting to change the AMI ID directly contradicts the design of the custom platform pipeline, where the platform definition file (which includes the AMI ID) is used only at creation time. Consequently, this action is not possible through the console or any API.
- ✓
Create a new platform version using the aws elasticbeanstalk create-platform-version command with an updated platform definition file.
Why this is correct
The correct procedure is to increment the version number in your platform definition file and then run the AWS CLI command `aws elasticbeanstalk create-platform-version`, which uploads the new packer template and associated configuration to build a fresh, immutable platform version. This new version can then be used as the `PlatformArn` in your environment's configuration, allowing the patched AMI to be deployed without affecting existing environments that reference the old version. This workflow is the documented way to apply changes to a custom platform.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.