DOP-C02 SDLC Automation Practice Question
A DevOps engineer notices that a CodePipeline execution fails at the deploy stage when deploying a Lambda function using AWS CloudFormation. The error message indicates that the stack update failed because the Lambda function's code is too large. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates confuse CodePipeline artifact size limits (which are much larger) with Lambda deployment package size limits, or incorrectly attribute the failure to CloudFormation template size limits or IAM permissions, when the error message directly indicates the Lambda code size is the issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function deployment package exceeds the maximum allowed size for Lambda.
The error message explicitly states that the Lambda function's code is too large, which directly points to the Lambda deployment package exceeding the maximum allowed size. AWS Lambda has a hard limit of 50 MB for zipped direct uploads (or 250 MB for container images), and CloudFormation will fail the stack update if the package exceeds this limit during a deploy stage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM role used by CloudFormation does not have sufficient permissions to update the Lambda function.
Why it's wrong here
A Lambda update through CloudFormation can indeed fail if the CloudFormation service role lacks lambda:UpdateFunctionCode permissions, but that failure surfaces as an authorization/access-denied exception (for example, 'API: lambda:UpdateFunctionCode ... is not authorized'), not as an object-size error. The question's failure is specifically size-related, so an IAM deficiency would produce a different exception message and would not explain a 'package too large' symptom.
- ✗
The CloudFormation template exceeds the maximum size limit for templates.
Why it's wrong here
CloudFormation enforces a hard template-size ceiling — 51,200 bytes for an inline template body and 460,800 bytes when the template is referenced from an S3 URL — and exceeding it fails with a 'Template format error' before any resource update is attempted. That limit applies to the template text itself, not to the deployment artifact in the pipeline's S3 bucket; a large Lambda package would not make the template too large.
- ✗
The artifact stored in the pipeline's S3 bucket exceeds the maximum allowed size for CodePipeline artifacts.
Why it's wrong here
CodePipeline does not define a maximum artifact size; artifacts are stored as compressed archives in the pipeline's S3 bucket, and S3 objects themselves can be as large as 5 TB. Therefore, even a Lambda package that is too large for Lambda would pass through the pipeline artifact stage without an error; the size check would only occur later when the Lambda service actually accepts or rejects the uploaded code.
- ✓
The Lambda function deployment package exceeds the maximum allowed size for Lambda.
Why this is correct
Lambda enforces hard quotas on deployment package size: 50 MB for a direct .zip upload, 250 MB for a .zip uploaded from an S3 bucket, and 250 MB for the uncompressed size including layers. In a CodePipeline/CloudFormation deployment, the Lambda code is staged in S3 and then referenced by CloudFormation; if that package exceeds Lambda's 250 MB uncompressed limit, the underlying API call returns a RequestEntityTooLargeException, which exactly matches the size-related failure observed.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.