Deploying Applications on AWS OpsWorks Using Custom Chef Recipes
A company uses AWS OpsWorks for configuration management of its EC2 instances. The DevOps team wants to apply a new security patch to all instances in a specific layer. What is the most efficient way to accomplish this?
⚠ Common exam trap
Candidates often choose Option D (Systems Manager Run Command) because it is a valid patching tool, but they overlook that OpsWorks provides a more integrated and efficient layer-wide mechanism via Chef recipes and lifecycle events, which is the intended pattern for configuration management within OpsWorks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the layer's custom Chef recipe to include the patch and trigger a lifecycle event to execute the recipe on all instances.
OpsWorks uses Chef to manage configuration, and updating the layer's custom Chef recipe to include the security patch allows you to trigger a lifecycle event (e.g., 'Setup' or 'Configure') that runs the recipe on all instances in that layer simultaneously. This approach is efficient, automated, and leverages OpsWorks' built-in configuration management without manual intervention or stack migration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new OpsWorks stack with the patch and migrate instances to it.
Why it's wrong here
Creating a new OpsWorks stack with the patch and migrating instances is unnecessarily complex and disruptive. It requires duplicating the entire stack configuration, manually reassociating resources like Elastic IPs and load balancers, and causes downtime during migration. OpsWorks is designed to manage configuration in place, so replacing the stack instead of updating it discards the benefits of automated, idempotent Chef recipes.
- ✗
SSH into each instance and run the patch command manually.
Why it's wrong here
SSHing into each instance to run the patch command manually is not scalable or automated. It introduces human error, leaves no centralized audit trail, and does not ensure consistent execution across the fleet. In environments with many instances, private subnets, or short-lived instances, this approach quickly becomes unmanageable and insecure, especially without proper key management and access controls.
- ✓
Update the layer's custom Chef recipe to include the patch and trigger a lifecycle event to execute the recipe on all instances.
Why this is correct
Updating the layer's custom Chef recipe to include the patch and triggering a lifecycle event is the correct, integrated approach. OpsWorks executes Chef recipes at well-defined lifecycle events (setup, configure, deploy, etc.), so attaching the patch logic to a recipe and invoking the event ensures consistent, automated application. This leverages the existing configuration management system, maintains versioned recipe code, and can be applied fleet-wide without manual intervention.
- ✗
Use AWS Systems Manager Run Command to run a patch command on each instance individually.
Why it's wrong here
AWS Systems Manager Run Command can execute a patch command on each instance, but it is not as integrated as OpsWorks' lifecycle events. Run Command requires the SSM Agent to be installed and the instances to be registered as managed nodes, which may not be true for OpsWorks-managed instances. Furthermore, it lacks the context of the Chef layer's configuration and does not natively map to the application's desired state, making it a patchwork solution rather than a cohesive configuration management practice.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.