DOP-C02 SDLC Automation Practice Question
A DevOps team is implementing a CI/CD pipeline for a microservices architecture on AWS ECS. They want to ensure zero-downtime deployments and automatic rollback if health checks fail. Which combination of services should they use?
⚠ Common exam trap
Watch out — candidates often assume AWS CodePipeline with rolling update (Option A) can handle automatic rollback, but CodePipeline itself does not manage deployment strategies or health-check-based rollbacks—those are handled by CodeDeploy, which is specifically designed for blue/green deployments with automatic rollback capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CodeDeploy with ECS blue/green deployment and CloudWatch alarms for automatic rollback.
AWS CodeDeploy supports blue/green deployments for ECS, which creates a new replacement task set alongside the original, allowing traffic to shift only after health checks pass. CloudWatch alarms can be configured to trigger an automatic rollback if the new deployment fails health checks, ensuring zero-downtime and automated recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CodePipeline with ECS rolling update and manual rollback.
Why it's wrong here
CloudOperations' rolling update in AWS ECS (default deployment controller) replaces tasks incrementally, which can briefly reduce capacity and may route requests to the new version before health checks pass. A manual rollback in CodePipeline means an operator must restart the pipeline, re-run an older stage, or update the task definition—expensive and error-prone. This partial traffic exposure combined with human-in-the-loop recovery makes it unsuitable for microservices that require zero-downtime deployments and instantaneous automatic rollback.
- ✓
AWS CodeDeploy with ECS blue/green deployment and CloudWatch alarms for automatic rollback.
Why this is correct
AWS CodeDeploy's ECS blue/green deployment creates a new 'green' task set with the new application version while preserving the original 'blue' task set and its target group. During the deployment, CodeDeploy shifts load balancer traffic from blue to green using a canary or linear strategy, and you can define post-deployment hooks and wait times. CloudWatch alarms, such as a failing health check on the green service or increased error rate, trigger a CodeDeploy rollback that automatically reroutes traffic to the blue task set and kills the green tasks. This gives microservices teams zero-downtime release with fully automated rollback—directly meeting the requirement.
- ✗
AWS Elastic Beanstalk with rolling deployment and enhanced health reporting.
Why it's wrong here
AWS Elastic Beanstalk is a PaaS service designed for classic web applications and single-container environments; it creates an Amazon EC2 instance or a single ECS cluster behind a load balancer, not a multi-service mesh for microservices. Enhanced health reporting in Elastic Beanstalk monitors infrastructure and application health at the environment level, but it cannot independently deploy or roll back individual microservices with their own release cycles. Therefore it would conflate all microservices into one environment, violating the independent deployability and scaling that the CI/CD pipeline for microservices expects.
- ✗
AWS CloudFormation with ECS service update and SNS notification on failure.
Why it's wrong here
AWS CloudFormation stack updates to an ECS service 'succeeds' once the ECS service reaches its desired count—CloudFormation does not wait for the new task set to pass health checks or for the application to become available at the service discovery or load balancer level. An SNS notification only tells operators after the fact that the stack update failed; it cannot alter traffic direction or initiate an application rollback based on a health check. Without health-check-aware gate logic or a custom-wait-condition Lambda, CloudFormation will report success even if the new version is broken, leaving bad code live.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps engineer is setting up a CI/CD pipeline for a microservices architecture. The team uses AWS CodeCommit, CodeBuild, and CodeDeploy. The engineer needs to ensure that the pipeline can automatically roll back the deployment if the health checks fail after deployment. Which action should the engineer take?
easy- A.Use AWS Lambda to monitor health checks and trigger a rollback via the CodeDeploy API.
- ✓ B.Configure the deployment group to roll back when a CloudWatch alarm is triggered.
- C.Set up the deployment group to use blue/green deployment with traffic shifting.
- D.Configure the pipeline to have a manual approval step after deployment.
Why B: CodeDeploy natively supports automatic rollbacks triggered by CloudWatch alarms. By configuring the deployment group to monitor a CloudWatch alarm (e.g., based on ELB health check metrics), CodeDeploy will automatically initiate a rollback to the last known good revision if the alarm enters the ALARM state, ensuring health check failures are handled without custom scripting.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.