DOP-C02 SDLC Automation Practice Question
A startup is using AWS CloudFormation to manage their infrastructure. They have a stack that creates an Amazon S3 bucket and an Amazon DynamoDB table. The stack was created successfully, but when they try to update the stack to add a new S3 bucket, the update fails with the error 'CREATE_FAILED - S3 bucket already exists'. The new bucket name is unique and does not exist. The template uses the same AWS::S3::Bucket resource type. What is the most likely cause?
⚠ Common exam trap
DOP-C02 often tests the misconception that 'unique name' means 'available name' — candidates forget that S3's global namespace retains deleted bucket names for an indeterminate period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket name was previously used and is still in the process of being deleted (bucket name not yet released).
S3 bucket names are globally unique across all AWS accounts and regions. When a bucket is deleted, its name is not immediately released — it enters a 'bucket name not yet available' state that can last from minutes to hours (historically up to 24 hours or longer). If the template tries to create a bucket with a name that was recently deleted, CloudFormation reports CREATE_FAILED with 'bucket already exists' even though the name appears unique to the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM user does not have permission to create S3 buckets.
Why it's wrong here
This cannot be the cause because the user already demonstrated s3:CreateBucket permission by successfully deploying the first stack that created the original bucket. CloudFormation uses the same IAM credentials for every API call in the stack operation, so if the permission had been revoked or was absent, the failure would surface as an Access Denied error rather than a bucket naming conflict. The actual error in this scenario, BucketAlreadyExists, proves authentication and authorization succeeded.
- ✓
The S3 bucket name was previously used and is still in the process of being deleted (bucket name not yet released).
Why this is correct
This is the correct answer because S3 bucket names are globally unique and are not released immediately after deletion. When a bucket is deleted, S3 enters a 'pending deletion' state where the name is still reserved for a variable period (usually minutes, sometimes up to an hour). Attempting to create a new bucket with that same name, whether through CloudFormation or the CLI, results in a BucketAlreadyExists (or BucketAlreadyOwnedByYou for the same account) error until the name is fully released. Since the stack previously managed a bucket with the same name and deleted it, the name is likely still in this cleanup window.
- ✗
The stack is in a different region than where the bucket is being created.
Why it's wrong here
The region where CloudFormation creates the bucket is irrelevant to name conflicts because S3 bucket names are global across all AWS Regions and accounts. A bucket name such as 'my-startup-bucket' is unique in the entire AWS namespace; only the data and endpoint are regional. While the stack is region-scoped, moving it to another region would not bypass the global uniqueness constraint, and a name still being finalized from a previous deletion would fail in any region.
- ✗
The CloudFormation template uses the wrong resource type for the bucket.
Why it's wrong here
The CloudFormation resource type AWS::S3::Bucket is the correct, official resource for provisioning an S3 bucket. If the template incorrectly used something like Custom::S3Bucket or a typo, CloudFormation would fail during template validation with an 'unknown resource type' error, long before attempting to create the bucket. The fact that the stack reached the point of issuing a bucket creation API call and received BucketAlreadyExists confirms the resource type is valid and parsed correctly.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.