DOP-C02 Configuration Management and IaC Practice Question
A company uses AWS OpsWorks for configuration management. They have a stack with a layer that includes several EC2 instances. The DevOps engineer needs to deploy a custom configuration file to all instances in the layer. What is the recommended approach?
⚠ Common exam trap
Candidates often confuse OpsWorks custom JSON with a mechanism to directly inject file content, when in reality it only provides attribute data to Chef recipes, and the actual file deployment must be handled by a recipe's file or template resource.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom Chef recipe and assign it to the layer's lifecycle events
AWS OpsWorks is a configuration management service that uses Chef. The recommended approach to deploy custom configuration files to all instances in a layer is to create a custom Chef recipe and assign it to the layer's lifecycle events (e.g., Setup, Configure, Deploy, or Shutdown). This ensures the recipe runs automatically on every instance in the layer at the appropriate stage of the instance lifecycle, providing a consistent and idempotent deployment method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use custom JSON in the stack settings to specify the file content
Why it's wrong here
Custom JSON in the stack settings is parsed by AWS OpsWorks and exposed as node attributes (e.g., node['custom_json'] or under the opsworks namespace) to Chef, but it does not directly create or write files on any instance. To actually place the file content, you must author a Chef recipe that consumes those attributes and uses a 'file' or 'template' resource to write to the desired path. Therefore, custom JSON alone cannot deliver the configuration file; it only supplies parameters that require a recipe to act on them.
- ✓
Create a custom Chef recipe and assign it to the layer's lifecycle events
Why this is correct
Create a custom Chef recipe that uses a 'file' or 'template' resource to generate the configuration content, then assign that recipe to the layer's lifecycle events, typically Setup or Configure. OpsWorks runs the recipe on every instance in the layer at the appropriate stage, making it the standard, lifecycle-aware mechanism for delivering managed configuration files. The recipe is idempotent and runs with full Chef knowledge of the stack, which is why this approach is the correct answer.
- ✗
Use AWS Systems Manager Run Command to copy the file
Why it's wrong here
AWS Systems Manager Run Command is a separate execution service that relies on the SSM Agent, not the OpsWorks agent, so it cannot be hooked into an OpsWorks layer's lifecycle events like Setup or Configure. While you could invoke a command manually or on a schedule, it has no awareness of OpsWorks stack configuration, Chef attributes, or layer membership, and it does not automatically reapply the file when the stack changes. This makes it a bolt-on automation tool that does not integrate with OpsWorks's configuration management lifecycle for delivering a managed file.
- ✗
Add the file to the instance's user data script
Why it's wrong here
User data is passed when the instance is launched and executed by cloud-init only once, during the initial boot, before OpsWorks has fully configured the layer. Existing instances that OpsWorks is already managing will never run this script, and it cannot be retargeted to a new lifecycle event or a layer membership change. Because OpsWorks is responsible for ongoing, convergent configuration management, a launch-only user-data script is the wrong mechanism for ensuring the configuration file exists and stays current across the fleet.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.