Courseiva
SDLC Automation →mediumMultiple Select

DOP-C02 SDLC Automation Practice Question

A DevOps team is designing a CI/CD pipeline for a microservices application that runs on Amazon ECS. They need to implement automated canary deployments. Which TWO AWS services would be essential for this implementation?

⚠ Common exam trap

A common mix-up: candidates confuse AWS CodeDeploy with AWS CloudFormation for deployment strategies, or mistakenly think EC2 Auto Scaling is needed for ECS canary deployments, when in fact CodeDeploy and CloudWatch are the essential pair for traffic shifting and monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CodeDeploy

AWS CodeDeploy is essential because it natively supports canary deployments for Amazon ECS through its ECS blue/green deployment type, allowing you to specify a canary traffic shift (e.g., 10% for 5 minutes) before full promotion. This enables automated, controlled rollouts with built-in rollback capabilities based on CloudWatch alarms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CodeDeploy

    Why this is correct

    AWS CodeDeploy is the native AWS service for performing canary deployments on Amazon ECS. It shifts a specified percentage of production traffic to the new task set (e.g., 10% for 5 minutes) while the old version continues to serve the rest, then gradually increases the new version's traffic until 100%. CodeDeploy orchestrates the entire traffic-shifting process using the AppSpec file, target groups, and optional LifecycleEventHooks such as BeforeAllowTraffic and AfterAllowTraffic, making it the correct choice for a microservices CI/CD pipeline requiring canary releases.

  • ✗

    AWS CloudFormation

    Why it's wrong here

    AWS CloudFormation is an infrastructure-as-code service that provisions and manages AWS resources, not a deployment service that orchestrates traffic shifting. While CloudFormation supports UpdatePolicy with RollingUpdate for ECS services, it only performs a rolling update by replacing tasks in batches; it cannot perform a canary deployment with controlled traffic percentages and automatic rollback based on live metrics. To achieve canary deployments, CloudFormation would need to be paired with CodeDeploy as a custom resource or via a CodePipeline action, but CloudFormation itself does not natively support canary traffic shifting, so it is incorrect in this context.

  • ✗

    AWS CodeBuild

    Why it's wrong here

    AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs unit tests, and produces build artifacts, but it is not a deployment service. CodeBuild can invoke deployment commands or integrate with CodeDeploy in a pipeline, yet it lacks any intrinsic capability to shift traffic, manage target groups, or define canary weights. For a microservices CI/CD pipeline requiring canary deployments, CodeBuild is typically the build stage component, while the actual deployment and traffic shifting must be handled by a service like CodeDeploy, making CodeBuild an incorrect standalone answer.

  • ✓

    Amazon CloudWatch

    Why this is correct

    Amazon CloudWatch is the observability service that provides metrics, logs, and alarms to monitor application health during a canary deployment. In a CodeDeploy ECS canary deployment, CloudWatch alarms are defined in the AppSpec to continuously evaluate metrics such as error rate, latency, or CPU utilization; if the alarm threshold is breached, CodeDeploy automatically rolls back the deployment to the original task set. However, CloudWatch does not perform the deployment itself—it only supplies the monitoring and automated rollback signal, so while it is a correct part of the solution, it is only one component and not the primary deployment orchestration tool.

  • ✗

    Amazon EC2 Auto Scaling

    Why it's wrong here

    Amazon EC2 Auto Scaling is designed to maintain a desired number of EC2 instances or manage the capacity of an ECS cluster via capacity providers; it has no role in controlling the flow of traffic between different application versions. Auto Scaling adjusts the number of instances based on load, but it does not understand deployment concepts like canary percentages, target groups, or traffic shifting, nor does it provide a mechanism to roll back a failed release. For a canary deployment, the orchestration responsibility lies with CodeDeploy, while Auto Scaling simply ensures the underlying compute capacity is sufficient; thus it is not directly related to the canary deployment strategy itself.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.