Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is troubleshooting an AWS CloudFormation stack that failed to create. The error message indicates that a resource 'AWS::Lambda::Function' timed out while being created. The Lambda function code is packaged as a ZIP file in Amazon S3. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda deployment package is very large, causing the S3 download to exceed the resource creation timeout.

AWS CloudFormation has a default timeout for creating resources, and if the Lambda deployment package is very large, downloading it from S3 can exceed that timeout. Option A is incorrect because the Lambda function's timeout setting (e.g., 3 seconds) applies to function execution, not to the creation process; the creation timeout is controlled by CloudFormation. Option B is incorrect because if the execution role lacks permissions to download the ZIP file, it would result in an access denied error, not a timeout. Option D is incorrect because the CloudFormation service role permissions affect stack operations broadly, but they do not directly cause a resource-specific timeout; the timeout here is due to package size.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function has a very short timeout (e.g., 3 seconds) configured in the function properties.

    Why it's wrong here

    The Timeout property on an AWS::Lambda::Function (e.g., 3 seconds) limits how long the function can run when invoked, not how long CloudFormation has to create the resource. The creation process—downloading the deployment package and registering the function—is not governed by this value. Even a 3-second timeout will not cause creation to fail; it only applies after the function is created and called at runtime.

  • ✗

    The Lambda function's execution role does not have permission to download the ZIP file from S3.

    Why it's wrong here

    The Lambda execution role grants permissions to the function when it runs (e.g., reading from S3, invoking services), and is not used by CloudFormation during resource creation. The S3 download during stack creation is performed by the CloudFormation service itself, which must have read access to the bucket—possibly via a CloudFormation service role. If the execution role lacked S3 permissions, you would see an access-denied error only when the function executes, not during creation.

  • ✓

    The Lambda deployment package is very large, causing the S3 download to exceed the resource creation timeout.

    Why this is correct

    If the ZIP file is exceptionally large (approaching Lambda's 50 MB compressed limit), the time CloudFormation takes to download it from S3 and create the Lambda resource can exceed the stack resource creation timeout. This manifests as a 'Resource creation timed out' error in the stack event, even though the function is valid. In contrast, a small package deploys quickly regardless of the Lambda function's configured timeout or role permissions.

  • ✗

    The CloudFormation service role does not have permissions to create Lambda functions.

    Why it's wrong here

    The CloudFormation service role (or the user's role) is what CloudFormation uses to make API calls to create resources. If that role lacks lambda:CreateFunction, the stack would fail with an 'API: lambda:CreateFunction AccessDenied' error, not a timeout. A timeout during resource creation points to the operation taking too long, not to a missing IAM permission. Thus, the correct diagnosis requires distinguishing between permission failures and duration overload.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.