Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps team is implementing infrastructure as code using AWS CloudFormation. They need to ensure that the stack can be updated to modify a resource's property that requires replacement. Which CloudFormation stack policy should they use?

⚠ Common exam trap

Many exam-takers confuse stack policies with IAM policies or assume that any policy statement (like AllowAll) is valid, when in fact CloudFormation stack policies require specific Effect, Action, and Resource keys, and the default behavior (no policy) already allows all updates, including replacement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No stack policy, or a policy that allows updates to all resources.

CloudFormation stack policies are designed to prevent accidental updates to critical resources, not to block updates that require replacement. By default, if no stack policy is applied, all resources can be updated, including those that require replacement. A policy that allows updates to all resources (or no policy) is necessary to permit a stack update that modifies a property requiring resource replacement, as the replacement process involves creating a new resource and deleting the old one, which is a valid update action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    No stack policy, or a policy that allows updates to all resources.

    Why this is correct

    With no stack policy, CloudFormation uses a default Allow policy that permits all update actions (Update:*) on every resource, so updates can proceed for any resource. Alternatively, an explicit stack policy with a statement containing Effect: Allow, Action: Update:*, Principal: *, and Resource: * has the same effect and also allows all resources to be updated. This matches the requirement to allow updates to all resources.

  • ✗

    A stack policy with an AllowAll statement.

    Why it's wrong here

    A stack policy is a JSON document that supports only Effect values of Allow or Deny in each Statement; 'AllowAll' is not a valid Effect, reserved word, or shorthand accepted by CloudFormation, so this policy would be rejected at validation time. Even if one intended to express an allow-all rule with a normal Allow statement, it would be redundant because the absence of a stack policy already defaults to allowing all updates. Therefore it is not the correct way to achieve an all-update policy.

  • ✗

    A stack policy with a DenyAll statement.

    Why it's wrong here

    A DenyAll stack policy would contain statements such as Effect: Deny with Action: Update:* and Resource: *, which explicitly blocks every update operation on the entire stack. Once such a policy is attached, CloudFormation rejects any attempt to update any resource, so it directly contradicts the goal of allowing updates to all resources. It is not a valid solution for the stated requirement.

  • ✗

    A stack policy that explicitly denies updates to the resource.

    Why it's wrong here

    A stack policy that explicitly denies updates to the resource would be scoped to that resource (Resource: the logical ID or physical ID) with a Deny for Update:* or specific update actions such as Update:Replace. That Deny statement overrides any Allow and prevents CloudFormation from modifying the resource during stack updates, causing the update to fail. Since the requirement is to allow updates to all resources, this policy is inappropriate.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.