DOP-C02 Configuration Management and IaC Practice Question
A DevOps team is designing a configuration management solution for a microservices architecture running on Amazon ECS. The team wants to ensure that container configurations are automatically updated when a new version of a parameter is stored in AWS Systems Manager Parameter Store. Which approach best meets this requirement with minimal operational overhead?
⚠ Common exam trap
Candidates often assume EventBridge with Lambda (Option D) is the simplest solution, but they overlook that AppConfig provides a managed, lower-overhead alternative specifically designed for configuration management and automatic deployment to ECS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS AppConfig to create a configuration profile that references the parameter. Configure a Lambda function as a validator and deploy strategy. When the parameter changes, AppConfig triggers a deployment that updates the ECS service.
AWS AppConfig is purpose-built for managing application configuration and supports automatic deployment of configuration changes to ECS services when a parameter in Systems Manager Parameter Store is updated. By creating a configuration profile that references the parameter, AppConfig can trigger a deployment that updates the ECS service without requiring custom code or manual intervention, minimizing operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS AppConfig to create a configuration profile that references the parameter. Configure a Lambda function as a validator and deploy strategy. When the parameter changes, AppConfig triggers a deployment that updates the ECS service.
Why this is correct
AWS AppConfig is purpose-built for this exact scenario because it separates configuration from code and provides a managed deployment lifecycle. By creating a configuration profile that references the SSM parameter, AppConfig treats each change as a new configuration version, runs your Lambda validator to catch malformed or unsafe values, and then rolls out the update using the specified deploy strategy (e.g., linear or canary with bake time). The ECS service is updated through AppConfig's integration with ECS—either via the AppConfig agent that supplies the new configuration or by triggering a task definition update—so the application receives the new value without a container rebuild. This gives you controlled rollout, automatic rollback on alarms, and auditability, which is exactly what a configuration management solution should provide.
- ✗
Use an AWS CloudFormation custom resource that updates the ECS service when the parameter changes.
Why it's wrong here
A CloudFormation custom resource is fundamentally a provisioning hook that runs only during stack create, update, or delete operations. It cannot react to an SSM parameter change on its own; you would need an external event (such as an EventBridge rule or a manual stack update) to invoke the custom resource, and even then it would only run once per Stack update, not continuously monitor the parameter. Moreover, custom resources are meant for infrastructure provisioning tasks like creating DNS records or waiting for an external service, not for dynamic runtime configuration changes. Relying on this approach adds orchestration overhead and eliminates CloudFormation's declarative benefits, so it is not a viable configuration management solution.
- ✗
Use a CI/CD pipeline that monitors the parameter store and triggers a new build and deploy of the container image with the updated parameter.
Why it's wrong here
This approach conflates configuration with code and forces an entire container image build and deployment every time a parameter changes, which is unnecessary and disruptive. Building a new image with the parameter baked in means you have to maintain image version sprawl and cannot easily promote a configuration change across environments without rebuilding artifacts. Additionally, a CI/CD pipeline is not natively event-driven by SSM Parameter Store changes—you would need to add polling or a webhook—and each deployment carries a risk of downtime and requires application restarts. Modern best practice is to inject configuration at runtime, not at build time, so this option is both over-engineered and architecturally incorrect.
- ✗
Use Amazon EventBridge to detect changes to the parameter and invoke a Lambda function that updates the ECS task definition and forces a new deployment.
Why it's wrong here
While EventBridge does emit Parameter Store change events and a Lambda function could call UpdateService to force a new deployment, this recreates a subset of AppConfig's features without the safety mechanisms. You would need to write custom code for deployment success/failure tracking, canary rollouts, automatic rollback, and configuration validation—all of which AppConfig provides natively. Additionally, a Lambda function that updates the ECS task definition and forces a new deployment bypasses AppConfig's ability to decouple configuration from code; it still forces a container restart and is more brittle because any Lambda error or mis-triggered event can cause an unintended deployment. This approach adds complexity and operational burden without leveraging the managed, auditable rollout capabilities that are essential for safe dynamic configuration management in production.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.