Courseiva
SDLC Automation →mediumMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CodePipeline to deploy a microservices application. The pipeline has a deploy action that uses AWS CloudFormation. The CloudFormation template creates an Amazon ECS service. The deployment fails because the ECS service cannot be updated. What is the most likely cause?

⚠ Common exam trap

Many candidates assume the error is due to missing IAM permissions or a misconfigured action type, but the real issue is CloudFormation's requirement that stacks be in a valid state before updates can proceed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CloudFormation stack already exists and is in a previous failed state.

When a CloudFormation stack update fails, the stack enters a ROLLBACK_COMPLETE or UPDATE_ROLLBACK_COMPLETE state. In this state, the stack is considered to be in a 'failed' state and cannot be updated again until it is either deleted or the stack is manually continued with a rollback. CodePipeline's CloudFormation deploy action will attempt to perform a stack update, but CloudFormation rejects the request because the existing stack is in a non-updatable state, causing the pipeline deployment to fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The CloudFormation stack already exists and is in a previous failed state.

    Why this is correct

    The CloudFormation stack referenced by the CodePipeline deploy action already exists and remains in a failed state (e.g., ROLLBACK_COMPLETE, UPDATE_ROLLBACK_COMPLETE, or CREATE_FAILED). CloudFormation refuses to perform an update on a stack that has not successfully reached a stable state (CREATE_COMPLETE or UPDATE_COMPLETE), so the deploy action fails immediately. A failed stack must be deleted (if resource policy allows) or updated/remediated using a change set to move it back to a stable, updatable state before CodePipeline can retry.

  • ✗

    The ECS service is in a steady state and cannot be modified.

    Why it's wrong here

    The ECS service being in a steady state (RUNNING and stable) does not prevent updates. Amazon ECS services are designed to be updated in-place while running—CloudFormation can update the task definition, desired count, or deployment configuration without stopping the service. A steady-state service is actually the normal, expected condition for an update, not a blocker. Therefore, this premise is factually incorrect as a cause of a pipeline deployment failure.

  • ✗

    The CodePipeline deploy action is configured with the wrong action type.

    Why it's wrong here

    The CodePipeline deploy action being configured with the wrong action type (e.g., using ECS instead of CloudFormation, or using the wrong provider category) would cause a different symptom—the action would attempt to call a different service or would not target the CloudFormation stack at all. If the action type were wrong, the pipeline might fail during validation or the update would never reach the CloudFormation stack. The failure described in this scenario is specifically a CloudFormation stack-level update failure, so the installed action type, while important, is not the root cause of this symptom.

  • ✗

    The IAM role used by CloudFormation does not have permission to update ECS services.

    Why it's wrong here

    An IAM role lacking permission to update ECS services would produce an authorization error, such as 'AccessDenied' or 'is not authorized to perform: ecs:UpdateService,' when CloudFormation attempts to perform the resource update. However, this would only happen after CloudFormation begins the update operation. If the stack is already in a failed state, CloudFormation will reject the update request upfront before even checking resource-level IAM permissions. Thus, while a missing permission is a plausible deployment issue, it does not explain an update failure caused by the stack's existing failed state.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.