Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer uses AWS CloudFormation to manage infrastructure. The stack creation fails with the error: 'Circular dependency between resources'. The template includes an EC2 instance, an Elastic IP, and an internet gateway. The instance is associated with the Elastic IP, and the Elastic IP uses the internet gateway for the VPC. Which resource relationship is MOST likely causing the circular dependency?

⚠ Common exam trap

Many candidates confuse the Elastic IP's dependency on the internet gateway (which is not direct) with the mutual dependency between the EC2 instance and the Elastic IP when the EIP uses the InstanceId property.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The EC2 instance depends on the Elastic IP, and the Elastic IP depends on the EC2 instance.

The circular dependency arises when the EC2 instance depends on the Elastic IP (via an Association resource) and the Elastic IP depends on the EC2 instance (via the InstanceId property). CloudFormation cannot resolve the creation order when two resources each require the other to exist first. This is a classic circular dependency in CloudFormation templates when using an AWS::EC2::EIP with an InstanceId that references the EC2 instance, while the instance itself has a DependsOn or a reference to the Elastic IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security group depends on the EC2 instance, and the EC2 instance depends on the security group.

    Why it's wrong here

    A security group is an independent, regional resource that filters traffic and never references an EC2 instance as a source or target; instead, an EC2 instance references the security group via its SecurityGroupIds property. Therefore, the only valid dependency is EC2 instance -> security group, not the reverse. If an ingress rule were to reference a security group ID, that would be a cross-security-group reference, not a dependency on an instance, so this option misdescribes the relationship.

  • ✗

    The Elastic IP depends on the internet gateway, and the internet gateway depends on the Elastic IP.

    Why it's wrong here

    An Elastic IP is allocated from the EC2 pool and exists independently of any internet gateway; it is associated with an instance or a network interface, not with a gateway. The internet gateway is attached to a VPC via a VPCGatewayAttachment resource, which depends on both the VPC and the gateway but not on the EIP. Thus, there is no dependency chain from EIP to IGW or IGW to EIP, making this pairing incorrect.

  • ✓

    The EC2 instance depends on the Elastic IP, and the Elastic IP depends on the EC2 instance.

    Why this is correct

    This is the correct circular dependency: if the EC2 instance declares DependsOn the Elastic IP (e.g., to ensure the IP exists before the instance starts) and the Elastic IP itself has a dependency on the instance (typically through an AWS::EC2::EIPAssociation resource, which requires the instance ID), CloudFormation cannot determine which resource to create first. The two resources form a closed loop, causing stack creation to fail with a circular dependency error. In practice you should let only the EIP association depend on the instance, or only the instance depend on the EIP, not both.

  • ✗

    The internet gateway depends on the VPC, and the VPC depends on the internet gateway.

    Why it's wrong here

    An internet gateway is created independently and then attached to a VPC using AWS::EC2::VPCGatewayAttachment, which has DependsOn or Ref to both the VPC and the gateway. The VPC itself does not require an internet gateway for its creation, so there is no VPC -> IGW dependency. The attachment resource creates the one-way dependency from the attachment to both, but this never forms a cycle, making this pairing incorrect.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.