Courseiva
SDLC Automation →mediumMultiple Choice

CloudFormation Resource Already Exists Error: Diagnosis and Fix

A team uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS instance. During an update, the stack fails with 'CREATE_FAILED' for the DB instance resource, and the error message indicates 'The DB instance already exists.' What is the most likely cause?

Quick Answer

The correct answer is that an RDS instance with the same identifier already exists in the account and region. This error occurs because CloudFormation, during a stack update or creation, attempts to provision a resource with a logical ID and physical name, but finds a pre-existing RDS instance using that exact DB instance identifier. The core technical concept here is that CloudFormation does not automatically manage resources left behind from a previously deleted stack; if the stack was deleted without retaining the resource, the orphaned RDS instance remains, causing a naming conflict when a new stack tries to create one with the same identifier. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this scenario tests your understanding of resource lifecycle management and the importance of checking for orphaned resources before redeploying. A common trap is confusing this with deletion protection, which prevents deletion but does not cause a CREATE_FAILED error for a new stack. Memory tip: "Orphaned ID, stack won't hide" — always verify that no resource with the same identifier exists in the account and region before attempting a new CloudFormation deployment.

⚠ Common exam trap

Many candidates confuse 'DeletionPolicy' or 'deletion protection' with the root cause, but the error is specifically about a duplicate identifier during creation, not about deletion or retention policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An RDS instance with the same identifier already exists in the account and region.

The error 'The DB instance already exists' indicates that CloudFormation is attempting to create a new RDS instance with a DB instance identifier that is already in use within the same AWS account and region. Since DB instance identifiers must be unique per account and region, the creation fails. This typically occurs when a stack update triggers a resource replacement (e.g., due to a property change that requires recreation) and the old instance was not deleted or its identifier is still reserved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An RDS instance with the same identifier already exists in the account and region.

    Why this is correct

    RDS enforces uniqueness of the DB instance identifier within an account and region, so CloudFormation's CREATE_FAILED reflects a naming collision with an existing instance rather than a template or permission fault. The stem's "already exists" error directly satisfies that constraint.

  • ✗

    The stack update is trying to replace the DB instance without a proper UpdateReplace policy.

    Why it's wrong here

    A missing UpdateReplacePolicy does not itself trigger a create collision; that policy governs what happens to the old resource after replacement, not whether CloudFormation attempts a duplicate create. It is tempting because replacement logic is involved, but the actual cause is a pre-existing instance outside the stack.

  • ✗

    The stack has a DeletionPolicy of Retain on the RDS instance.

    Why it's wrong here

    Retain keeps the old RDS instance after removal from the stack, so a replacement create can collide with the orphaned instance, but the error arises from the create attempt itself, not the policy. Retain is tempting because it preserves resources, which is correct when deliberately keeping data after stack deletion.

  • ✗

    The RDS instance has deletion protection enabled.

    Why it's wrong here

    Deletion protection blocks deletion of an existing RDS instance; it does not cause CloudFormation to attempt creating a duplicate and report that the instance already exists. It is tempting because it also concerns RDS lifecycle, but it applies to preventing accidental removal, not to create collisions.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A startup is using AWS CloudFormation to manage their infrastructure. They have a stack that creates an Amazon S3 bucket and an Amazon DynamoDB table. The stack was created successfully, but when they try to update the stack to add a new S3 bucket, the update fails with the error 'CREATE_FAILED - S3 bucket already exists'. The new bucket name is unique and does not exist. The template uses the same AWS::S3::Bucket resource type. What is the most likely cause?

easy
  • A.The IAM user does not have permission to create S3 buckets.
  • ✓ B.The S3 bucket name was previously used and is still in the process of being deleted (bucket name not yet released).
  • C.The stack is in a different region than where the bucket is being created.
  • D.The CloudFormation template uses the wrong resource type for the bucket.

Why B: S3 bucket names are globally unique across all AWS accounts and regions. When a bucket is deleted, its name is not immediately released — it enters a 'bucket name not yet available' state that can last from minutes to hours (historically up to 24 hours or longer). If the template tries to create a bucket with a name that was recently deleted, CloudFormation reports CREATE_FAILED with 'bucket already exists' even though the name appears unique to the user.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.