Courseiva

DOP-C02 Configuration Management and IaC Practice Question

An organization uses OpsWorks to manage application stacks. They notice that custom cookbooks are not being executed during the lifecycle events. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse IAM permissions with repository access, assuming the layer's IAM role controls cookbook retrieval, when in fact OpsWorks uses separate SSH keys or S3 bucket policies for repository access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The custom cookbook repository URL is misconfigured or inaccessible

Custom cookbooks in AWS OpsWorks are fetched from a repository (e.g., Git, S3, HTTP) during lifecycle events. If the repository URL is misconfigured (e.g., wrong branch, invalid path) or inaccessible (e.g., private repo without proper SSH keys or S3 bucket permissions), OpsWorks cannot retrieve the cookbooks, causing them to not execute. This is the most common cause of cookbook execution failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The layer's IAM role does not have permissions to execute the cookbook

    Why it's wrong here

    An IAM role governs permissions for API calls to AWS services such as EC2, S3, or CloudWatch, but Chef cookbook execution is a local process on the instance. The OpsWorks agent invokes the Chef client to run recipes from the local cookbook cache, and that process does not rely on the instance's IAM role to authorize cookbook permissions. If the IAM role had insufficient policy statements, you would instead see API-level failures for any AWS resources the recipes attempt to manage, not a total failure to execute the cookbook itself.

  • ✓

    The custom cookbook repository URL is misconfigured or inaccessible

    Why this is correct

    OpsWorks Stacks downloads custom cookbooks from the source repository during the setup phase and then runs the recipes defined for each lifecycle event. If the repository URL is malformed, points to a private repo with invalid credentials, or the endpoint is unreachable, the agent cannot retrieve the cookbook and therefore cannot execute any recipes. The failure may appear as 'non-execution' because the instance comes online but nothing from the cookbook is applied, and the error is only visible if you inspect the OpsWorks agent logs or stack activity.

  • ✗

    The cookbook is not configured with CodeDeploy

    Why it's wrong here

    CodeDeploy is a separate AWS deployment service that is not involved in how OpsWorks Stacks executes Chef cookbooks. In an OpsWorks stack, lifecycle events such as Setup, Configure, Deploy, and Undeploy are mapped to Chef recipes, and those recipes are run by the Chef client installed on the instance. A cookbook does not need any CodeDeploy configuration, and mentioning it confuses two independent deployment mechanisms; if the cookbook were truly missing from the Chef run list, that would be an OpsWorks layer configuration issue, not a CodeDeploy issue.

  • ✗

    The cookbook uses a Chef version that is not supported by OpsWorks

    Why it's wrong here

    OpsWorks Stacks supports multiple Chef versions (from 0.9 to 12, including Chef 11 and Chef 12), and the cookbook is executed by the Chef version chosen when the stack is created. If the cookbook were written for an incompatible Chef version, you would typically see a 'chef-client' error or a syntax/runtime failure in the logs, not complete silence—the agent would still attempt to run and report the error. Moreover, you can manage the Chef version via the stack settings, so an unsupported version is not a plausible cause of the cookbook not running without any diagnostic output.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.