Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "cloudformation.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

A DevOps team is troubleshooting a CloudFormation stack creation failure. The stack uses a service role with the trust policy shown in the exhibit. The error message states: 'Insufficient permissions to create the resource'. Which action should the team take to resolve this issue?

⚠ Common exam trap

Watch out — candidates often confuse a stack policy (which controls update protection) with IAM permissions, or they think modifying the trust policy (who can assume the role) fixes a missing permissions issue, when in reality the role's attached policies must grant the actual resource creation actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach IAM policies to the service role that grant permissions to create the resources.

The error 'Insufficient permissions to create the resource' indicates that the service role used by CloudFormation lacks the necessary IAM permissions to perform the resource creation actions. The trust policy shown in the exhibit allows CloudFormation to assume the role, but the role itself must have IAM policies attached that grant the required permissions (e.g., ec2:*, s3:*). Option D is correct because attaching the appropriate IAM policies to the service role resolves the permission issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the CloudFormation template to use the user's IAM role instead of a service role.

    Why it's wrong here

    CloudFormation cannot simply 'use the user's IAM role' because a service role must have a trust policy that allows the CloudFormation service principal (cloudformation.amazonaws.com) to assume it; a user role is intended for interactive or programmatic access by a person and does not include that trust relationship. Even if the user's role has broad permissions, passing it as the stack's role will fail with a validation error or, if it can be assumed, violate least-privilege by granting CloudFormation the same full access a user possesses. The template itself does not declare IAM roles; the role ARN is supplied at stack creation or update time, so modifying the template would not address the underlying permissions problem.

  • ✗

    Create a new stack policy that allows the required actions.

    Why it's wrong here

    A stack policy is an IAM resource-based policy attached to a CloudFormation stack that controls which update operations (e.g., Update:Modify, Update:Delete) can be performed on specific resources during a stack update. It does not grant any permissions to CloudFormation or to the underlying AWS services; it only prevents accidental changes by filtering the actions CloudFormation may attempt. The failure to create resources is an authorization failure on the resource API calls made by the service role, so adding a stack policy cannot resolve a missing IAM permission for the role.

  • ✗

    Add the user's IAM role to the trust policy.

    Why it's wrong here

    The trust policy of the service role defines which principals (services or accounts) are allowed to assume that role. Adding the user's IAM role as a trusted entity would permit that user role to assume the service role, but it would still not permit CloudFormation to assume it, because the service principal 'cloudformation.amazonaws.com' is not listed. This misconfiguration could even worsen security by creating a privilege escalation path where a user role with lower privileges can assume a role that has resource-creation permissions. The fix must instead update the trust policy to include the CloudFormation service principal only.

  • ✓

    Attach IAM policies to the service role that grant permissions to create the resources.

    Why this is correct

    To resolve the stack creation failure, you must attach IAM policies to the service role that explicitly allow the actions needed to create the resources declared in the template, such as ec2:CreateSecurityGroup on the appropriate resource ARN. CloudFormation assumes the service role at the start of the stack operation and uses the role's permissions to make the resource API calls; without a policy granting those actions, the API calls will be denied even if the user's own credentials have broad access. Use managed policies or an inline policy that grants only the required resource types to follow least privilege, and verify the role's trust policy still allows CloudFormation to assume it.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.