Courseiva
SDLC Automation →easyMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CloudFormation to manage infrastructure. They want to deploy a stack that creates an S3 bucket and a DynamoDB table. The S3 bucket name must be unique across all AWS accounts. Which CloudFormation intrinsic function should be used to generate a unique bucket name?

⚠ Common exam trap

Many candidates think `!Ref 'AWS::StackName'` or `!Ref 'AWS::Region'` provide sufficient uniqueness, but they overlook the requirement for global uniqueness across all AWS accounts, which only `AWS::AccountId` guarantees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

!Sub 'mybucket-${AWS::AccountId}'

The `!Sub 'mybucket-${AWS::AccountId}'` intrinsic function substitutes the AWS::AccountId pseudo parameter, which is guaranteed to be unique per AWS account. Since S3 bucket names must be globally unique across all AWS accounts, appending the account ID ensures the generated name does not conflict with buckets in other accounts. This approach is a common pattern for creating unique resource names in CloudFormation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    !Ref 'AWS::StackName'

    Why it's wrong here

    The AWS::StackName pseudo parameter is simply the user-defined name of the CloudFormation stack, which is not guaranteed to be unique across accounts, regions, or even over time as stacks are deleted and recreated. Because S3 bucket names live in a global namespace, relying on stack name alone would easily lead to collisions with buckets created by other stacks in other accounts. Additionally, stack names can contain characters invalid in S3 bucket names, so using it directly is neither safe nor valid.

  • ✗

    !GetAtt S3Bucket.Arn

    Why it's wrong here

    The !GetAtt S3Bucket.Arn function returns an attribute of an existing resource, which is resolved only after the bucket has been successfully created. When defining the BucketName property of the same bucket, the ARN is not yet available during template evaluation, creating a circular dependency that CloudFormation cannot resolve. Moreover, the ARN itself contains the bucket name, so it cannot be used as the input to define that same name—this makes the approach fundamentally impossible.

  • ✓

    !Sub 'mybucket-${AWS::AccountId}'

    Why this is correct

    AWS::AccountId is a true pseudo parameter that is resolved during template evaluation, providing a unique, numeric identifier for the current AWS account. When combined with a fixed prefix like 'mybucket-', the resulting bucket name is globally unique across all accounts and regions because each account has a distinct ID, satisfying S3's global namespace requirement. This approach is deterministic, readable, and avoids the circular dependency issues of resource attributes, making it a widely adopted best practice for naming resources.

  • ✗

    !Select [0, !Split ['-', !Ref 'AWS::Region']]

    Why it's wrong here

    This expression extracts only the first segment of the region name, such as 'us' from 'us-east-1', which is an extremely coarse grouping and not remotely unique—countless buckets would share the same name when using this logic. Even the full region name alone would not be globally unique across accounts, but this truncated version fails even faster. Since S3 bucket names must be unique worldwide, this option cannot possibly guarantee the required uniqueness for the bucket name.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.