DOP-C02 SDLC Automation Practice Question
A DevOps team uses AWS CloudFormation with nested stacks. They are experiencing stack update failures because changes to a nested stack cause resource conflicts. Which THREE best practices should they follow to manage nested stack updates? (Choose THREE.)
⚠ Common exam trap
Watch out — candidates often think disabling rollback (Option A) or using DependsOn (Option E) can prevent or manage update conflicts, but these options do not address the root cause of resource conflicts in nested stacks; instead, stack policies, change sets, and resource import are the correct best practices for managing such conflicts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a stack policy to prevent updates to critical resources in the nested stacks.
Applying a stack policy to nested stacks prevents updates to critical resources, avoiding conflicts during nested stack updates. Stack policies act as a guard to deny updates to specified resources, which is essential when changes to a nested stack might cause resource conflicts or unintended modifications. This best practice ensures that only intended changes are applied, reducing the risk of update failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the stack update to disable rollback to allow debugging of failures.
Why it's wrong here
Disabling rollback during a CloudFormation update leaves the stack in a partially updated, failed state (UPDATE_FAILED), which is especially dangerous with nested stacks because the parent and child stacks become inconsistent and require manual, error-prone recovery. Instead, you should keep rollback enabled so CloudFormation automatically restores the last known good state, and use logs and change sets to debug the root cause before attempting another update. Disabling rollback does not aid in debugging; it only prolongs the failure and risks exposing broken infrastructure to production traffic.
- ✓
Apply a stack policy to prevent updates to critical resources in the nested stacks.
Why this is correct
A stack policy is an IAM-like policy that specifically controls which update actions are permitted on resources within a given CloudFormation stack. When applied to each nested stack—not just the root stack—it can explicitly deny update, replace, or delete operations on critical resources, even if a change set or direct update attempts to modify them. This serves as an enforcement layer that complements change sets, which are only advisory, and ensures that accidental modifications are blocked at the resource level. Stack policies are the correct way to protect nested stack resources from unintended changes.
- ✓
Use the resource import feature to bring existing resources under CloudFormation management.
Why this is correct
The resource import feature lets you bring an existing AWS resource into CloudFormation management without recreating it, which is a best practice for eliminating drift and ensuring all critical resources are under Infrastructure as Code control. By importing resources that were originally created outside CloudFormation, you can then apply stack policies and change sets to them uniformly, reducing the chance of accidental modifications from unmanaged changes. Import is not a direct protection mechanism, but it expands the governance scope so that no resource remains outside the safety of CloudFormation, thereby preventing future accidental changes caused by ad-hoc modifications.
- ✓
Use AWS CloudFormation change sets to review changes before executing updates.
Why this is correct
CloudFormation change sets generate a detailed preview of the exact modifications that an update will perform—showing whether a resource will be added, removed, or replaced, and highlighting property-level changes—before any execution. This allows the DevOps team to inspect the impact on critical nested stack resources and catch unintended modifications, such as the replacement of a stateful database or a change to an IAM policy, prior to deployment. Change sets are a recommended best practice because they provide a safe review checkpoint, but they require manual approval and are not a blocking control by themselves; they must be used in conjunction with stack policies for full protection.
- ✗
Use DependsOn to ensure nested stacks are updated in a specific order.
Why it's wrong here
Using DependsOn to force an order between nested stack resources is incorrect because CloudFormation already determines the appropriate update order based on the dependency graph and resource relationships. DependsOn is intended for explicit resource-level dependencies within a single stack; when applied to nested stacks, it can easily lead to circular dependencies (e.g., stack A depends on B, and B depends on A) and makes the template brittle and difficult to maintain. Furthermore, nested stacks are orchestrated by the parent stack automatically, so manually enforcing ordering with DependsOn is unnecessary and can cause update failures that are hard to troubleshoot.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.