Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is using AWS CloudFormation to deploy a stack that includes a VPC with public and private subnets. The engineer wants to ensure that the public subnets automatically get a public IP address assigned to instances launched in them. Which property should be set?

⚠ Common exam trap

Many candidates confuse VPC-level DNS settings (`EnableDnsSupport` and `EnableDnsHostnames`) with subnet-level public IP assignment, or they mistakenly think the instance-level `AssociatePublicIpAddress` is the only way to control public IP assignment, ignoring the subnet-level auto-assign feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MapPublicIpOnLaunch on the subnet

The `MapPublicIpOnLaunch` property on an AWS CloudFormation `AWS::EC2::Subnet` resource controls whether instances launched in that subnet automatically receive a public IP address. Setting this property to `true` ensures that any EC2 instance launched in the public subnet gets a public IPv4 address from the subnet's CIDR range, which is essential for internet-facing resources in a VPC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EnableDnsSupport on the VPC

    Why it's wrong here

    EnableDnsSupport is a VPC-level attribute that only toggles whether the VPC uses Amazon's DNS resolver for private DNS names, such as internal Route 53 records. It does not influence the allocation of public IPv4 addresses to instances or subnets, so modifying it would have no effect on public IP assignment. To automatically assign public IPs to every instance launched in a subnet, you must enable the subnet-level MapPublicIpOnLaunch attribute instead.

  • ✓

    MapPublicIpOnLaunch on the subnet

    Why this is correct

    MapPublicIpOnLaunch is a subnet-level attribute that, when set to true, automatically assigns a public IPv4 address to every instance's primary network interface upon launch. This is the correct control for achieving subnet-wide public IP assignment, as it directly applies at the subnet boundary and affects all instances regardless of individual launch configuration. Changing this attribute is the standard CloudFormation approach to provision instances in a public subnet with reachable IP addresses.

  • ✗

    EnableDnsHostnames on the VPC

    Why it's wrong here

    EnableDnsHostnames is a VPC-level attribute that controls whether instances are assigned DNS hostnames by the AWS DNS service; it works alongside EnableDnsSupport but only affects hostname resolution, not network addressing. It does not cause instances to receive public IP addresses, nor does it alter subnet-level network interface behavior. The attribute is completely orthogonal to public IP assignment, so it cannot be used to make instances publicly reachable.

  • ✗

    AssociatePublicIpAddress on the instance

    Why it's wrong here

    AssociatePublicIpAddress is a property of an instance's network interface that can be set during EC2 launch to request a public IPv4 address for that specific instance. However, the question specifically asks for a subnet-level configuration, and this setting is instance-level only, overriding subnet defaults individually. The correct subnet-level way to assign public IPs to all instances is to set MapPublicIpOnLaunch on the subnet, not to configure each instance separately.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.