Courseiva

DOP-C02 Incident and Event Response Practice Question

Exhibit

Refer to the exhibit.

# AWS CloudFormation stack event log
2024-03-01 12:00:00 UTC  UPDATE_IN_PROGRESS  AWS::ECS::Service  MyService
2024-03-01 12:01:00 UTC  UPDATE_FAILED  AWS::ECS::Service  MyService  Resource update cancelled
2024-03-01 12:01:00 UTC  UPDATE_ROLLBACK_IN_PROGRESS  AWS::ECS::Service  MyService
2024-03-01 12:05:00 UTC  UPDATE_ROLLBACK_COMPLETE  AWS::ECS::Service  MyService

A DevOps engineer updates an ECS service via CloudFormation. The stack update fails with the message 'Resource update cancelled'. The engineer notices that the ECS service's desired count was temporarily reduced during the update. What is the most likely cause of the failure?

⚠ Common exam trap

Many exam-takers confuse the 'Resource update cancelled' error with a permissions or circuit breaker issue, but the key clue is the temporary reduction in desired count, which directly points to a minimum healthy percent constraint that prevents the service from scaling down to zero.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ECS service's minimum healthy percent was set to 100, causing the desired count reduction to zero to be rejected.

The error 'Resource update cancelled' occurs because CloudFormation detected that the ECS service update was not progressing as expected. When the minimum healthy percent is set to 100, the deployment process cannot reduce the desired count to zero (or below the current running count) without violating the requirement that 100% of the tasks remain healthy. This causes the update to be cancelled as CloudFormation waits indefinitely for the deployment to complete, eventually timing out and rolling back.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ECS service's minimum healthy percent was set to 100, causing the desired count reduction to zero to be rejected.

    Why this is correct

    During a rolling update, CloudFormation temporarily sets the ECS service's desired count to zero to force a clean replacement of all tasks. If the service's minimumHealthyPercent is set to 100%, ECS cannot scale the current running tasks below 100% of the desired count, so the service scheduler rejects the desired count reduction and the CloudFormation update is cancelled. This is a common misconfiguration when engineers expect zero-downtime but inadvertently block the scale-in step.

  • ✗

    The ECS service's target group had an unhealthy instance that prevented the deregistration.

    Why it's wrong here

    An unhealthy instance in the target group would affect the deployment's ability to maintain traffic health, but it does not prevent the ECS service from being updated; the service would simply replace the unhealthy task or trigger a deployment failure. The deregistration process is managed by the target group, not tied to the CloudFormation update cancellation. Moreover, the cancellation occurs before any task is actually deployed, and unhealthy instances would only matter during the health check phase, not during the desired count adjustment.

  • ✗

    The ECS service deployment circuit breaker was triggered due to a timeout.

    Why it's wrong here

    The deployment circuit breaker is an ECS feature that automatically triggers a rollback when a new deployment fails to stabilize, typically due to tasks failing health checks or reaching the maximum percent. It does not apply to a CloudFormation update cancellation, which is a client-side operation that occurs when the service scheduler rejects a change like a desired count adjustment. The circuit breaker is activated during an active deployment, not when the update request is initially rejected.

  • ✗

    The ECS service did not have the required IAM role to call ecs:UpdateService.

    Why it's wrong here

    If the IAM role lacked permission to call ecs:UpdateService, the CloudFormation stack update would fail with an AccessDenied error, and CloudFormation would mark the stack as UPDATE_FAILED. That is not the same as the update being 'cancelled'; a cancellation indicates the request was received but rejected by the ECS service logic. Another subtle point: CloudFormation uses the credentials of the caller, not the service's IAM role, to perform API calls, so the service's role itself is irrelevant to this failure.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.