DOP-C02 Configuration Management and IaC Practice Question
A DevOps team is designing a CI/CD pipeline for a microservices application using AWS CodePipeline. They want to incorporate infrastructure as code (IaC) using AWS CloudFormation. Which three practices should they follow to ensure reliable and repeatable deployments? (Choose THREE.)
⚠ Common exam trap
The trap here is that candidates might think monolithic templates simplify management (Option C) or that skipping change sets speeds up pipelines (Option D), but both compromise reliability and repeatability, which are core to IaC best practices in the DOP-C02 exam.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the same CloudFormation template across all environments, with parameterization for environment-specific values.
Using a single CloudFormation template across all environments with parameterization ensures consistency and reduces drift. Environment-specific values (e.g., instance sizes, subnet IDs) are passed as parameters, so the same template logic applies to dev, test, and prod, making deployments repeatable and auditable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the same CloudFormation template across all environments, with parameterization for environment-specific values.
Why this is correct
Parameterizing a single CloudFormation template enables a consistent infrastructure definition across dev, test, and prod, with environment-specific variables (e.g., instance types, VPC IDs, AMI IDs) passed via Parameters and Mappings. This avoids template drift and duplication, ensuring the same resource logic is tested and promoted. It also simplifies change management because a single template revision can be reused for multiple environments.
- ✓
Implement rollback triggers to automatically roll back failed stack updates.
Why this is correct
Rollback triggers in AWS CloudFormation monitor CloudWatch alarms during a stack update; if an alarm breaches (e.g., high error rate or latency), the stack automatically rolls back to the last known-good state. This reduces the time to recover from a failed deployment by eliminating manual intervention. RollbackConfiguration can be applied in the stack creation/update call to specify alarm ARNs and a monitoring window.
- ✗
Create a single monolithic template for all microservices to simplify management.
Why it's wrong here
A single monolithic CloudFormation template that includes every microservice creates a tight coupling of completely independent lifecycles. This makes stack updates extremely slow and risky, as a change in one service may force re-evaluation of all resources, and a failure in any service can cause the entire stack to roll back. It also violates the principle of least privilege, making IAM roles and resource policies unnecessarily broad.
- ✗
Skip change sets during stack updates to speed up the pipeline.
Why it's wrong here
Change sets provide a preview of the resources that will be added, modified, or deleted when a CloudFormation stack is updated, allowing you to validate the impact before actually executing the update. Skipping change sets removes this visibility, so an apparently simple change (e.g., an AMI ID parameter) could accidentally delete an RDS database or replace an EC2 instance with no prior warning. In a CI/CD pipeline, this increases the chance of unintended downtime or data loss.
- ✓
Use CloudFormation stack sets to deploy stacks across multiple accounts and regions consistently.
Why this is correct
AWS CloudFormation StackSets let you deploy a stack to multiple accounts and regions simultaneously, which is ideal for enforcing consistent infrastructure across an AWS Organization. StackSets handle account onboarding/offboarding via stack set instances, and you can update all associated stacks with a single StackSet update operation. However, they do not replace per-environment parameterization; you still need to use the same template with environment parameters to maintain separation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.