DOP-C02 SDLC Automation Practice Question
A team uses AWS CloudFormation to manage infrastructure. They want to deploy a stack that creates an S3 bucket and a DynamoDB table. The S3 bucket name must be unique across all AWS accounts. Which CloudFormation intrinsic function should be used to generate a unique bucket name?
⚠ Common exam trap
Many candidates think `!Ref 'AWS::StackName'` or `!Ref 'AWS::Region'` provide sufficient uniqueness, but they overlook the requirement for global uniqueness across all AWS accounts, which only `AWS::AccountId` guarantees.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
!Sub 'mybucket-${AWS::AccountId}'
The `!Sub 'mybucket-${AWS::AccountId}'` intrinsic function substitutes the AWS::AccountId pseudo parameter, which is guaranteed to be unique per AWS account. Since S3 bucket names must be globally unique across all AWS accounts, appending the account ID ensures the generated name does not conflict with buckets in other accounts. This approach is a common pattern for creating unique resource names in CloudFormation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
!Ref 'AWS::StackName'
Why it's wrong here
The AWS::StackName pseudo parameter is simply the user-defined name of the CloudFormation stack, which is not guaranteed to be unique across accounts, regions, or even over time as stacks are deleted and recreated. Because S3 bucket names live in a global namespace, relying on stack name alone would easily lead to collisions with buckets created by other stacks in other accounts. Additionally, stack names can contain characters invalid in S3 bucket names, so using it directly is neither safe nor valid.
- ✗
!GetAtt S3Bucket.Arn
Why it's wrong here
The !GetAtt S3Bucket.Arn function returns an attribute of an existing resource, which is resolved only after the bucket has been successfully created. When defining the BucketName property of the same bucket, the ARN is not yet available during template evaluation, creating a circular dependency that CloudFormation cannot resolve. Moreover, the ARN itself contains the bucket name, so it cannot be used as the input to define that same name—this makes the approach fundamentally impossible.
- ✓
!Sub 'mybucket-${AWS::AccountId}'
Why this is correct
AWS::AccountId is a true pseudo parameter that is resolved during template evaluation, providing a unique, numeric identifier for the current AWS account. When combined with a fixed prefix like 'mybucket-', the resulting bucket name is globally unique across all accounts and regions because each account has a distinct ID, satisfying S3's global namespace requirement. This approach is deterministic, readable, and avoids the circular dependency issues of resource attributes, making it a widely adopted best practice for naming resources.
- ✗
!Select [0, !Split ['-', !Ref 'AWS::Region']]
Why it's wrong here
This expression extracts only the first segment of the region name, such as 'us' from 'us-east-1', which is an extremely coarse grouping and not remotely unique—countless buckets would share the same name when using this logic. Even the full region name alone would not be globally unique across accounts, but this truncated version fails even faster. Since S3 bucket names must be unique worldwide, this option cannot possibly guarantee the required uniqueness for the bucket name.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.