DOP-C02 Configuration Management and IaC Practice Question
An organization uses AWS OpsWorks for configuration management. They have a stack with multiple layers, including a PHP application layer and a MySQL database layer. The operations team needs to deploy a custom configuration file to all PHP application instances. How should this be accomplished using OpsWorks?
⚠ Common exam trap
Test-takers frequently confuse stack-level custom cookbooks (which apply to all layers) with layer-specific lifecycle event assignments, leading them to choose Option B, which would incorrectly deploy the configuration file to the MySQL layer as well.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom cookbook with a recipe that deploys the configuration file, and assign it to the Deploy lifecycle event of the PHP layer.
OpsWorks uses Chef cookbooks to manage configuration. By creating a custom cookbook with a recipe that deploys the configuration file and assigning it to the Deploy lifecycle event of the PHP layer, the recipe runs on all PHP application instances during deployment, ensuring the file is placed correctly. This approach leverages OpsWorks' built-in lifecycle events and Chef's idempotent execution model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the OpsWorks agent to directly copy the file to each instance via SSH.
Why it's wrong here
The OpsWorks agent is a background daemon that manages instance communication with the AWS service and runs Chef clients, but it is not an SSH client or file transfer tool. Manually SSHing into each PHP instance to copy the configuration file bypasses OpsWorks lifecycle management entirely, leaving no automated record and requiring repeated manual effort on every instance and every instance replacement. This approach is neither idempotent nor scalable, and it fails to re-apply the file when a new instance is added to the layer.
- ✗
Add the configuration file as a stack-level custom cookbook and assign it to all layers.
Why it's wrong here
In OpsWorks Stacks, assigning a custom cookbook at the stack level only makes the cookbook's recipes available to all layers, but to actually run a recipe you must attach it to a layer's lifecycle event. If you attach the recipe to all layers rather than only the PHP layer, every instance in the stack—including web servers, load balancers, or databases—would execute the recipe, potentially writing PHP-specific configuration to the wrong host. This violates the requirement to target only PHP instances and can cause configuration drift or service disruption on non-PHP layers.
- ✓
Create a custom cookbook with a recipe that deploys the configuration file, and assign it to the Deploy lifecycle event of the PHP layer.
Why this is correct
A custom cookbook can contain a recipe with Chef resources like 'template' or 'file' that renders the configuration file content to the exact path expected by PHP on each instance. Assigning that recipe to the Deploy lifecycle event of the PHP layer ensures it runs only during a deployment operation on that layer, and only on instances that belong to the PHP layer. This approach is fully automated, idempotent, and version-controlled, and it aligns with OpsWorks best practices by using the layer-specific lifecycle hook to scope execution precisely.
- ✗
Use a custom JSON attribute in the stack settings to define the file content, and then use a built-in recipe to apply it.
Why it's wrong here
Custom JSON attributes in the stack settings are indeed injected as Chef node attributes and are accessible to recipes during Chef runs. However, built-in OpsWorks recipes (such as those from the PHP or Apache cookbooks) have no generic logic that automatically takes a custom JSON attribute and writes it to a file without a custom recipe. Thus, merely defining the file content in custom JSON does nothing unless you also write a recipe to consume those attributes and create the file resource; without that custom recipe, the built-in recipes will ignore the attribute or fail to produce the expected configuration.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization uses AWS OpsWorks for configuration management of their EC2 instances. They need to ensure that all instances have the latest security patches applied automatically. Which action should the team take?
easy- ✓ A.Configure a custom Chef recipe in OpsWorks to run 'yum update' on a schedule.
- B.Create an AWS Config rule to check for missing patches and trigger an auto-remediation.
- C.Update the AMI used by the OpsWorks layer to include the latest patches.
- D.Enable AWS Systems Manager Patch Manager to patch all instances managed by OpsWorks.
Why A: AWS OpsWorks uses Chef recipes for configuration management. To ensure instances have the latest security patches automatically, the team should configure a custom Chef recipe that runs 'yum update' (or equivalent) on a schedule. This leverages OpsWorks' native automation capabilities. Therefore, option A is correct.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.