DOP-C02 Configuration Management and IaC Practice Question
A DevOps engineer is troubleshooting a CloudFormation stack that is in UPDATE_ROLLBACK_FAILED state. The stack attempted to update an Auto Scaling group but failed due to insufficient capacity in the Availability Zone. What is the recommended next step?
⚠ Common exam trap
Many exam-takers think manually fixing the underlying issue (e.g., increasing capacity) is sufficient to resolve the rollback failure, but they overlook that CloudFormation requires an explicit ContinueUpdateRollback API call to exit the UPDATE_ROLLBACK_FAILED state, even after the root cause is addressed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the ContinueUpdateRollback operation to skip the resources that failed
When a CloudFormation stack is in UPDATE_ROLLBACK_FAILED state, the recommended next step is to use the ContinueUpdateRollback operation with the 'ResourcesToSkip' parameter to skip the resources that failed during rollback. This allows CloudFormation to complete the rollback of the remaining resources and move the stack to a stable state, after which you can investigate and fix the underlying issue (e.g., insufficient capacity in the AZ) before attempting the update again. Option C directly aligns with AWS documentation for handling this specific stack state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Execute a new stack update with the same template
Why it's wrong here
Executing a new stack update with the same template is invalid because CloudFormation does not allow any new update operation while the stack is in the UPDATE_ROLLBACK_FAILED state. This state indicates that both the original update and the automatic rollback failed, leaving the stack in a stuck condition. A regular update cannot override this; you must first resolve the rollback failure using ContinueUpdateRollback, optionally skipping the problematic resources. Attempting a new update will only be rejected by the CloudFormation service.
- ✗
Manually increase the Auto Scaling group capacity in the affected AZ
Why it's wrong here
Manually increasing the Auto Scaling group capacity in the affected Availability Zone is a non-invasive workaround that does not address the underlying CloudFormation stack failure. The stack remains in UPDATE_ROLLBACK_FAILED, and CloudFormation still considers the last update unsuccessful. Moreover, modifying a CloudFormation-managed resource outside of the service introduces configuration drift, which can cause subsequent stack operations to fail or produce unexpected results. This action neither recovers the rollback nor restores the stack to a stable state.
- ✓
Use the ContinueUpdateRollback operation to skip the resources that failed
Why this is correct
The ContinueUpdateRollback operation is the correct remediation because it explicitly resumes the failed rollback, allowing CloudFormation to finish reverting the stack to its last known good state. By specifying ResourcesToSkip, you can instruct CloudFormation to skip the specific resources that caused the rollback to fail, such as resources with external dependencies that cannot be rolled back automatically. This is the documented, supported approach to recover a stack stuck in UPDATE_ROLLBACK_FAILED. Once the rollback completes, the stack returns to a usable state, and you can then address the skipped resource manually.
- ✗
Delete the Auto Scaling group and recreate it
Why it's wrong here
Deleting the Auto Scaling group and recreating it is an overly destructive and risky approach that will likely cause service disruption and data loss. Because the Auto Scaling group is managed by CloudFormation, manually deleting it will create a mismatch between the actual resources and the stack's template, leaving the stack in an inconsistent state. Furthermore, recreation does not resolve the stack's UPDATE_ROLLBACK_FAILED status; CloudFormation still requires you to explicitly recover via ContinueUpdateRollback. Manual deletion also bypasses the safety mechanisms of CloudFormation, potentially breaking the stack's ability to manage related resources.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.