DOP-C02 Configuration Management and IaC Practice Question
A DevOps engineer is troubleshooting an AWS CloudFormation stack that failed to create. The error message indicates that a resource 'AWS::Lambda::Function' timed out while being created. The Lambda function code is packaged as a ZIP file in Amazon S3. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda deployment package is very large, causing the S3 download to exceed the resource creation timeout.
AWS CloudFormation has a default timeout for creating resources, and if the Lambda deployment package is very large, downloading it from S3 can exceed that timeout. Option A is incorrect because the Lambda function's timeout setting (e.g., 3 seconds) applies to function execution, not to the creation process; the creation timeout is controlled by CloudFormation. Option B is incorrect because if the execution role lacks permissions to download the ZIP file, it would result in an access denied error, not a timeout. Option D is incorrect because the CloudFormation service role permissions affect stack operations broadly, but they do not directly cause a resource-specific timeout; the timeout here is due to package size.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Lambda function has a very short timeout (e.g., 3 seconds) configured in the function properties.
Why it's wrong here
The Timeout property on an AWS::Lambda::Function (e.g., 3 seconds) limits how long the function can run when invoked, not how long CloudFormation has to create the resource. The creation process—downloading the deployment package and registering the function—is not governed by this value. Even a 3-second timeout will not cause creation to fail; it only applies after the function is created and called at runtime.
- ✗
The Lambda function's execution role does not have permission to download the ZIP file from S3.
Why it's wrong here
The Lambda execution role grants permissions to the function when it runs (e.g., reading from S3, invoking services), and is not used by CloudFormation during resource creation. The S3 download during stack creation is performed by the CloudFormation service itself, which must have read access to the bucket—possibly via a CloudFormation service role. If the execution role lacked S3 permissions, you would see an access-denied error only when the function executes, not during creation.
- ✓
The Lambda deployment package is very large, causing the S3 download to exceed the resource creation timeout.
Why this is correct
If the ZIP file is exceptionally large (approaching Lambda's 50 MB compressed limit), the time CloudFormation takes to download it from S3 and create the Lambda resource can exceed the stack resource creation timeout. This manifests as a 'Resource creation timed out' error in the stack event, even though the function is valid. In contrast, a small package deploys quickly regardless of the Lambda function's configured timeout or role permissions.
- ✗
The CloudFormation service role does not have permissions to create Lambda functions.
Why it's wrong here
The CloudFormation service role (or the user's role) is what CloudFormation uses to make API calls to create resources. If that role lacks lambda:CreateFunction, the stack would fail with an 'API: lambda:CreateFunction AccessDenied' error, not a timeout. A timeout during resource creation points to the operation taking too long, not to a missing IAM permission. Thus, the correct diagnosis requires distinguishing between permission failures and duration overload.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.