DOP-C02 SDLC Automation Practice Question
A DevOps team is implementing infrastructure as code using AWS CloudFormation. They want to ensure that stack updates are reviewed and approved before execution. Which feature should they use?
⚠ Common exam trap
A common mix-up: candidates confuse stack policies (which control update permissions) with change sets (which provide a preview and approval workflow), leading them to select stack policies as the mechanism for review and approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change Sets
Change Sets allow you to preview the proposed changes to a CloudFormation stack before executing them. This enables the DevOps team to review and approve modifications, ensuring that only validated updates are applied. By creating a change set, you can see exactly which resources will be added, modified, or deleted, and then decide whether to execute it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Drift detection
Why it's wrong here
Drift detection is a monitoring feature in AWS CloudFormation that compares the live state of a stack's resources to the intended template configuration, reporting any manual modifications made outside of CloudFormation. It identifies discrepancies after they occur, but it does not provide a preview or approval mechanism for proposed changes. For a DevOps team seeking a controlled review process before applying infrastructure modifications, drift detection only offers post-hoc awareness rather than a pre-application gate.
- ✗
Stack policies
Why it's wrong here
Stack policies are JSON documents that define which update actions can be performed on specific resources within a CloudFormation stack, serving as protective guards against accidental deletions or modifications. They enforce resource-level safeguards but do not generate a summary of pending changes or offer a workflow for stakeholders to review and approve updates. Thus, while stack policies address safety and authorization, they lack the human-in-the-loop review capability that is essential for a change management process.
- ✗
StackSets
Why it's wrong here
StackSets enable CloudFormation to simultaneously deploy and manage stacks across multiple AWS accounts and Regions by defining a single template and set of parameters. They are designed for multi-account orchestration and consistent rollouts, not for examining the detailed impact of a proposed update on existing resources. In a scenario focused on reviewing changes before applying them to a single stack, StackSets are operationally misaligned and do not provide an approval mechanism.
- ✓
Change Sets
Why this is correct
Change Sets in AWS CloudFormation generate a read-only summary of the exact resource-level actions (Update, Add, Remove) that would result from submitting a new template or parameters. They act as a dry-run, allowing the team to inspect the proposed modifications, identify resources that will be replaced, and evaluate potential downtime before executing the stack update. This review-and-approve capability makes Change Sets the ideal tool for implementing infrastructure as code with controlled change management.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.