DOP-C02 Configuration Management and IaC Practice Question
A DevOps team is troubleshooting a CloudFormation stack creation failure. The error message states: 'CREATE_FAILED: Resource handler returned message: "You have attempted to create more resources than the current AWS account limit"'. Which step should the team take to resolve this issue?
⚠ Common exam trap
Test-takers frequently confuse a service limit error with an IAM permissions issue or a template syntax error, leading them to choose options B or C instead of recognizing the need to check and increase AWS service quotas.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the current service limits for the resource type and request a limit increase from AWS Support.
The error message explicitly indicates that the CloudFormation stack creation failed because the AWS account has reached a service limit for a specific resource type. Option D is correct because the team must first identify which resource type exceeded its limit (e.g., EC2 instances, VPCs, or IAM roles) by checking the AWS Service Quotas console or using the Trusted Advisor dashboard, then request a limit increase from AWS Support. Simply retrying the stack creation or modifying IAM permissions will not resolve a hard service quota violation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the failed stack and recreate it with the same template.
Why it's wrong here
Deleting the failed stack and recreating it with the identical template will usually reproduce the same LimitExceeded failure, because rollback already cleans up any partially provisioned resources and the account-level quota for the resource type remains unchanged. Unless another stack or resource is deleted to free capacity, the recreate will hit the same hard limit. The correct action is to increase the quota before redeploying.
- ✗
Review the IAM permissions for the CloudFormation service role.
Why it's wrong here
Reviewing the IAM permissions of the CloudFormation service role would only address AccessDenied errors, not LimitExceededException. The error message explicitly states that an account limit has been reached, which means the request was authenticated and authorized, but the resource type's quota in that region is exhausted. IAM misconfigurations cannot produce a 'limit reached' error.
- ✗
Modify the CloudFormation template to use a different resource type.
Why it's wrong here
Switching to a different resource type in the template is an architectural workaround that avoids the specific quota only by changing what you deploy, which may not satisfy the application's actual requirements. For instance, switching from one database engine to another does not reduce the number of security groups or VPCs needed. The proper resolution is to request a quota increase for the original resource type rather than altering the design to sidestep a service limit.
- ✓
Check the current service limits for the resource type and request a limit increase from AWS Support.
Why this is correct
When CloudFormation returns an error that an account limit has been reached, it means the AWS resource API rejected the creation request due to service quota exhaustion for that resource type in the current region. You should use the Service Quotas console or AWS Support to check the current limit and request an increase, then wait for approval before retrying the stack creation. This directly resolves the root cause without modifying the template or IAM role.
Visual reference
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.