Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Exhibit

Refer to the exhibit.

Error log from AWS CloudFormation stack update:

"Resource handler returned message: 'User: arn:aws:sts::123456789012:assumed-role/AdminRole/UpdateUser is not authorized to perform: ec2:DescribeSubnets on resource: arn:aws:ec2:us-east-1:123456789012:subnet/subnet-0bb1c79de3EXAMPLE' (Service: Ec2, Status Code: 403, Request ID: ...)"

A DevOps engineer receives the error shown in the exhibit when attempting to update an existing CloudFormation stack that deploys a VPC with subnets. The stack was created successfully earlier using the same template. What is the most likely cause of this error?

⚠ Common exam trap

Many exam-takers assume the error is due to a template syntax issue or resource conflict, but the real cause is insufficient IAM permissions for the update operation, which is a subtle but critical distinction in CloudFormation stack management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role used for the stack update lacks the 'ec2:DescribeSubnets' permission.

When updating a CloudFormation stack that deploys a VPC with subnets, the update operation must be able to read the current state of the subnet resources to determine if changes are needed. The IAM role used for the stack update must have the 'ec2:DescribeSubnets' permission to query the existing subnet configuration. Without this permission, CloudFormation cannot verify the subnet's current properties, leading to the error shown in the exhibit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The subnet ID in the template is already used by another stack in the same account.

    Why it's wrong here

    The subnet ID already being in use by another stack is not a valid cause for this error. AWS allows multiple stacks to reference the same subnet ID; there is no global uniqueness constraint that would block a CloudFormation update. The error message clearly refers to an authorization failure (ec2:DescribeSubnets), not a resource conflict like 'Subnet already used'.

  • ✓

    The IAM role used for the stack update lacks the 'ec2:DescribeSubnets' permission.

    Why this is correct

    CloudFormation uses the IAM service role's permissions when performing stack updates. If the role lacks ec2:DescribeSubnets, the update fails with an access denied error, exactly as shown in the exhibit. This permission is required for CloudFormation to validate the subnet and retrieve its attributes during the update. Adding ec2:DescribeSubnets to the role's policy resolves the issue.

  • ✗

    The subnet specified in the template does not exist in the selected AWS region.

    Why it's wrong here

    If a subnet did not exist, CloudFormation would return a validation error such as 'Subnet ID not found' or a resource-not-found message, not an authorization error. The error shown is an explicit AccessDenied, indicating the configuration exists but the caller lacks permission to describe it. This points to an IAM policy issue rather than a nonexistent resource.

  • ✗

    The CloudFormation template has a syntax error in the subnet definition.

    Why it's wrong here

    A syntax error in the template would be detected during template parsing before any IAM authorization checks occur. CloudFormation would respond with a validation error describing the syntax line, not an AccessDenied from ec2:DescribeSubnets. Since the error is a permission failure from the IAM role, the template syntax is not the cause.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.