Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

A DevOps engineer is designing a CI/CD pipeline for a microservices architecture. The pipeline must deploy to Amazon ECS using blue/green deployments. The team wants to automatically roll back if the new deployment fails health checks. Which combination of AWS services and configurations should the engineer use?

⚠ Common exam trap

Many exam-takers assume CodePipeline's ECS action supports automatic rollback, but it only provides a deployment action without native health check monitoring or rollback logic, requiring additional custom steps or manual intervention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CodeDeploy with an ECS compute platform, configure a CloudWatch alarm for health checks, and enable automatic rollback.

AWS CodeDeploy with an ECS compute platform natively supports blue/green deployments for Amazon ECS, including automatic rollback triggered by CloudWatch alarms. By configuring a CloudWatch alarm based on ECS service health checks (e.g., ELB target group health), CodeDeploy can automatically revert to the original blue task set if the new green deployment fails, meeting the requirement for zero-touch rollback.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS CodeDeploy with an ECS compute platform, configure a CloudWatch alarm for health checks, and enable automatic rollback.

    Why this is correct

    CodeDeploy with the ECS compute platform natively orchestrates blue/green deployments by shifting traffic between the original and replacement ECS task sets using a load balancer target group. You can associate CloudWatch alarms with the deployment and enable automatic rollback so that if health checks or custom metrics fail, CodeDeploy reverts traffic to the original task set without manual intervention. This is the only option that combines native ECS support, health monitoring, and automated rollback.

  • ✗

    Use AWS CloudFormation with a custom resource to perform blue/green deployment.

    Why it's wrong here

    A CloudFormation custom resource would require you to author and maintain a Lambda function to orchestrate ECS service updates, target group registration, and traffic shifting, all of which CodeDeploy already provides. Moreover, CloudFormation rollback is triggered only by stack creation/update failures, not by post-deployment health checks, so you would need to build and manage your own rollback logic inside the custom resource. This adds significant complexity and operational risk compared to a managed deployment service.

  • ✗

    Use AWS Elastic Beanstalk with blue/green environment swapping.

    Why it's wrong here

    Elastic Beanstalk is a platform-as-a-service offering for running web applications, not a control plane for ECS services; it does not deploy Docker containers to an Amazon ECS cluster as a first-class target. While Elastic Beanstalk supports blue/green environment swap, that swap swaps DNS CNAME records between Beanstalk environments and does not provide deployment-level health check rollback for ECS microservices. Therefore it is architecturally incompatible with the stated ECS pipeline requirement.

  • ✗

    Use AWS CodePipeline with ECS deployment action and manual approval for rollback.

    Why it's wrong here

    The CodePipeline ECS deployment action can update your ECS service with a new task definition, but adding a manual approval step does not create any automatic rollback behavior; it simply pauses the pipeline for human approval before proceeding. If the deployment fails health checks, the pipeline has no built-in mechanism to revert traffic to the previous task set unless you manually re-run a prior pipeline stage or build separate rollback logic. Automatic rollback requires CodeDeploy's deployment groups and CloudWatch alarm integration, not a manual approval gate.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.