Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is creating a CloudFormation template that includes an AWS Lambda function. The function code is stored in an S3 bucket. The engineer wants to ensure that the Lambda function is updated whenever the code in S3 changes. What should the engineer do?

⚠ Common exam trap

Candidates often assume any automation tool (CodePipeline or CodeDeploy) can replace the need for explicit version tracking, but CloudFormation requires a property change to trigger an update, and only referencing the S3 object version achieves that directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reference the S3 object version in the Lambda function's Code property to force an update when the version changes

Referencing the S3 object version in the Lambda function's Code property (e.g., `S3ObjectVersion`) creates a dependency on that specific version. When the S3 object is updated, its version changes, which triggers CloudFormation to detect a change in the template and update the Lambda function during the next stack update. This ensures the function code is refreshed without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CodeDeploy to deploy the Lambda function

    Why it's wrong here

    AWS CodeDeploy is a deployment service that manages traffic shifting and rollbacks for Lambda function versions, but it is not an S3 event source. CodeDeploy only acts when a deployment is explicitly initiated via the CLI, console, or a pipeline; it cannot detect a new object upload to an S3 bucket and automatically trigger a Lambda code update. Even if you ran a CodeDeploy deployment, CloudFormation's template state would remain unchanged, so the function could be updated outside of the stack, but that does not directly address the requirement to force a stack update when the S3 object changes. The fundamental problem here is CloudFormation's diff-based update detection, which CodeDeploy does not influence.

  • ✓

    Reference the S3 object version in the Lambda function's Code property to force an update when the version changes

    Why this is correct

    In a CloudFormation template, the Lambda function's Code property, when referencing an S3 bucket, can include the S3ObjectVersion attribute. Because CloudFormation treats any template property change as a stack update trigger, explicitly specifying the object version creates a new template value whenever the zip file in S3 is modified. Without this version, CloudFormation compares only the bucket and key, both of which stay constant, so it considers the resource unrmodified and skips the Lambda update—even if the S3 object's contents were replaced. Adding the S3ObjectVersion forces a resource replacement or update, making it the simplest and most direct way to ensure the stack updates on code changes.

  • ✗

    Add a DependsOn clause to the Lambda function resource

    Why it's wrong here

    The DependsOn attribute in CloudFormation is used to establish explicit resource creation or update ordering between resources within the same stack, such as creating a bucket before a custom resource. It gives CloudFormation no information about whether a Lambda function's source code has changed. With a Lambda function whose code lives in S3, CloudFormation's update detection relies entirely on changes to the resource properties—primarily the Code property—so a DependsOn clause does not supply a new property value or signal that the S3 object version has changed. Therefore, even with DependsOn, CloudFormation will still report no update when the zip file is re-uploaded to the same S3 key.

  • ✗

    Use AWS CodePipeline to automatically update the stack when the S3 object changes

    Why it's wrong here

    AWS CodePipeline can orchestrate a full CI/CD workflow, including detecting S3 source changes and triggering a CloudFormation stack update, so it is technically feasible. However, it is a heavyweight solution when the core issue is that the template's Code property does not change when the S3 object's contents change; CodePipeline would invoke UpdateStack, but CloudFormation would still see the same bucket/key and skip the Lambda update. To make CodePipeline work, you'd still need to incorporate the S3 object version (or a similar unique identifier) into the template parameters or function code, which means the version reference is the true root-cause fix. Given the requirement asks for what the engineer should do directly with the template, adding the S3ObjectVersion is simpler and avoids unnecessary pipeline infrastructure.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.