Courseiva
SDLC Automation →easyMultiple Choice

DOP-C02 SDLC Automation Practice Question

Network Topology
$ aws cloudformation describe-stack-eventsstack-name my-stackRefer to the exhibit.```"StackEvents": ["EventId": "Event-1","StackName": "my-stack","LogicalResourceId": "my-stack","ResourceStatus": "ROLLBACK_IN_PROGRESS","Timestamp": "2024-01-01T00:00:00Z"},"EventId": "Event-2","LogicalResourceId": "MyLambdaFunction","ResourceStatus": "CREATE_FAILED","ResourceStatusReason": "Resource creation cancelled",

Refer to the exhibit. A DevOps engineer created a CloudFormation stack that includes a Lambda function. The stack creation failed and rolled back. The error message for the Lambda function says 'Resource creation cancelled'. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse 'Resource creation cancelled' with a resource-specific failure (e.g., insufficient permissions), but this error indicates CloudFormation cancelled the resource due to a failure in another resource during stack creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The stack rollback was triggered due to a failure in another resource, and the Lambda creation was cancelled.

CloudFormation creates resources in a specific order, and if a dependency fails or another resource fails, CloudFormation cancels the creation of subsequent resources and initiates a rollback. The error 'Resource creation cancelled' indicates that the Lambda function was never actually attempted to be created; instead, its creation was aborted due to a failure in a preceding or parallel resource. This is a standard CloudFormation behavior when a stack operation is interrupted by a failure in another resource.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function's IAM role does not have sufficient permissions.

    Why it's wrong here

    An insufficient IAM role on the Lambda function would surface as an AccessDeniedException or a similar permissions error when CloudFormation calls lambda:CreateFunction. This is a distinct failure from the status shown in the exhibit, which indicates the creation was cancelled rather than denied. A permissions problem would also typically appear consistently in the function's own resource status, whereas a stack-wide rollback cancels multiple resources simultaneously.

  • ✗

    The Lambda function's code is missing from the S3 bucket.

    Why it's wrong here

    If the Lambda deployment package were missing, the CloudFormation service would receive a NoSuchKey or 404 error from Amazon S3 while attempting to retrieve the object. That error would be reported directly as the resource status reason, not as a cancellation. The cancellation message means CloudFormation never got to a point of validating the code because the creation was interrupted by an external stack failure.

  • ✓

    The stack rollback was triggered due to a failure in another resource, and the Lambda creation was cancelled.

    Why this is correct

    CloudFormation creates stack resources in parallel where no dependencies exist, and a failure in any resource triggers an automatic rollback that cancels all other in-progress resource creations. When the Lambda function's AWS::Lambda::Function resource is cancelled in this way, CloudFormation marks it as CREATE_FAILED with the reason 'Resource creation cancelled' — even though the Lambda service never reported an error. The root cause lies in a different resource that failed first, so you must inspect the full stack event list to identify the original failure.

  • ✗

    The Lambda function creation timed out.

    Why it's wrong here

    A Lambda function creation timeout is not a normally reported event for an AWS::Lambda::Function resource; CloudFormation would instead show a timeout-related error for custom resources that use a CreationPolicy or a Custom:: resource. If the Lambda service had failed to respond, the reason would say 'timed out' or include a timeout error code, not 'Resource creation cancelled'. Cancellation is an orchestration action taken by CloudFormation, not a service-side timeout.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. The exhibit shows a CloudFormation stack event. The stack creation failed with 'Resource creation cancelled'. What is the most likely reason for this cancellation?

easy
  • A.The stack template contains a syntax error.
  • B.The IAM role used for stack operations lacks permissions.
  • C.A stack creation timeout was reached.
  • ✓ D.The stack was manually cancelled by a user or an automation script.

Why D: The 'Resource creation cancelled' event in a CloudFormation stack creation indicates that the operation was explicitly halted by a user or an automation script (e.g., via the AWS CLI, Console, or SDK). This is distinct from a timeout or permission error, which would produce different error messages such as 'Resource creation timed out' or 'API: cloudformation:CreateStack Access Denied'.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.