Courseiva
SDLC Automation →easyMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment strategy is Blue/Green. During a recent deployment, the new instances passed all health checks, but traffic was not routed to them. What is the most likely reason?

⚠ Common exam trap

Watch out — candidates often assume health check success guarantees traffic routing, but in AWS, health checks only verify instance readiness; traffic routing depends on separate load balancer listener rules and target group associations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The target group associated with the Auto Scaling group is not properly configured to route traffic.

In a Blue/Green deployment with CodeDeploy and an Auto Scaling group, traffic routing is handled by a load balancer target group. If the target group is not properly configured to route traffic to the new instances (e.g., missing or incorrect listener rules, deregistration delay, or health check thresholds), the instances may pass health checks but never receive traffic. This is the most likely cause because the deployment succeeded in provisioning and validating the new instances, but the load balancer did not forward requests to them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The target group associated with the Auto Scaling group is not properly configured to route traffic.

    Why this is correct

    The target group tied to the Auto Scaling group acts as the traffic-routing endpoint for the load balancer. If its health check path, port, or timeout settings are misconfigured—or if it is not attached to the appropriate listener rule—the newly deployed instances will be registered but immediately marked unhealthy and deregistered, so no user traffic reaches them. CodeDeploy itself successfully completes its scripts, but the deployment outcome appears as a routing failure, not an instance-level failure.

  • ✗

    The deployment group is not configured to use a load balancer.

    Why it's wrong here

    If the deployment group lacked a load balancer, CodeDeploy would block the blue/green deployment from starting because traffic shifting requires a defined load balancer or target group. The fact that instances were launched and the deployment reached a routing stage indicates a load balancer and target group are present; otherwise you'd see a configuration error before any instances are provisioned. Thus, a missing load balancer cannot be the underlying cause here.

  • ✗

    The Auto Scaling group's lifecycle hook failed to signal readiness.

    Why it's wrong here

    A lifecycle hook failure in the Auto Scaling group would keep the new instance in the 'Pending' state, preventing CodeDeploy from even executing its deployment scripts on that instance. Even if the hook succeeded without signaling, the instance would not transition to InService and would never be targeted by the deployment. The observed symptom—instances running but receiving no traffic—points to a condition after the instance is healthy, specifically the target group's routing or health-check configuration, not a pre-deployment hook issue.

  • ✗

    The CodeDeploy agent on the new instances is not installed.

    Why it's wrong here

    An absent CodeDeploy agent would cause the deployment to fail with an 'Instance failed to complete' error because the service needs the agent to run the AppSpec lifecycle events. The instance would be terminated or marked as a failed replacement, and the deployment would stop rather than leave instances in a running state with no traffic. Since the described situation involves running instances that just aren't routed to, the agent is clearly functional and this is a routing problem instead.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.