DOP-C02 Configuration Management and IaC Practice Question
A DevOps engineer is designing a CI/CD pipeline for a microservices architecture on AWS. They want to use AWS CodeDeploy to deploy applications to an Auto Scaling group. The pipeline must ensure that only a small percentage of instances are updated at a time, and if health checks fail, the deployment is automatically rolled back. Which deployment configuration should be used?
⚠ Common exam trap
The trap is equating 'small percentage' with HalfAtATime (50% is not small) or assuming blue/green is always safer — but blue/green does not meet the explicit 'small percentage of instances updated at a time' wording in the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In-place deployment with 'CodeDeployDefault.OneAtATime' configuration and automatic rollback enabled.
`CodeDeployDefault.OneAtATime` deploys to one instance at a time, which is the smallest possible batch and satisfies the 'small percentage of instances' requirement. Enabling automatic rollback ensures that if health checks fail, CodeDeploy reverts to the last known good revision, meeting the rollback requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Blue/green deployment with a fixed number of instances.
Why it's wrong here
Blue/green deployment with a fixed number of instances replaces the entire environment at once; traffic is cut over from the old environment to the new environment, so the blast radius is 100% of the fleet, not a small percentage. Even if the new environment has the same fixed instance count, you cannot gradually shift a small percentage of traffic instance-by-instance without implementing additional weighted routing, which is not described here. It also doubles infrastructure cost during the deployment and is overkill for a change that needs a controlled, small rollout.
- ✗
In-place deployment with 'CodeDeployDefault.AllAtOnce' configuration.
Why it's wrong here
In-place deployment with 'CodeDeployDefault.AllAtOnce' configuration instructs CodeDeploy to deploy to all instances in the deployment group simultaneously, meaning every instance is updated in the same deployment event. This maximizes the blast radius and provides no opportunity to validate the new revision on a small subset before the whole fleet is affected. It directly violates the requirement to rollout to a small percentage of instances at a time, as there is no staged progression or health-check pause between instances.
- ✗
In-place deployment with 'CodeDeployDefault.HalfAtATime' configuration.
Why it's wrong here
In-place deployment with 'CodeDeployDefault.HalfAtATime' configuration divides the fleet into two halves and deploys to the first half, waits for health checks, then deploys to the second half. The step size is fixed at 50% of the instances in the deployment group, which is far too coarse for a requirement to update a small percentage at a time. If the target small percentage is, say, 5-10%, a 50% stage gives no protection against a bad revision affecting half of the production traffic before rollback can trigger.
- ✓
In-place deployment with 'CodeDeployDefault.OneAtATime' configuration and automatic rollback enabled.
Why this is correct
In-place deployment with 'CodeDeployDefault.OneAtATime' configuration is the built-in CodeDeploy strategy that stages the deployment to a single instance at a time, waiting for the instance to pass health checks before proceeding to the next. When the fleet size is reasonably large, one instance represents a small percentage of total traffic, satisfying the gradual rollout requirement. Enabling automatic rollback ensures that if any instance fails its health check or a deployment hook returns a non-zero exit code, CodeDeploy immediately redeploys the previous revision and stops the deployment, minimizing impact.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.