Courseiva

DOP-C02 · topic practice

Configuration Management and IaC practice questions

This domain covers provisioning and managing AWS infrastructure and instance configuration as code. It is tested through scenario questions on CloudFormation templates and change sets, nested stacks and drift, StackSets, AWS CDK and SAM, plus Systems Manager State Manager, Patch Manager, Automation runbooks, and OpsCenter for fleet-wide configuration at scale.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Configuration Management and IaC

What the exam tests

What to know about Configuration Management and IaC

Be able to read and write CloudFormation or CDK templates, use change sets for controlled deployments, and configure Systems Manager Patch Manager and State Manager for instance compliance. The single most important thing: know which resource and feature actually performs the required action, not just its general purpose.

Choosing Systems Manager Patch Manager baselines and maintenance windows for EC2 patching compliance

Using CloudFormation change sets to review stack changes before execution

Authoring VPC templates with subnets, route tables, NAT gateways, and Internet gateways

Diagnosing CodePipeline CloudFormation deployment failures such as throttling and rate exceeded errors

Watch out for

Common Configuration Management and IaC exam traps

  • ▸Assuming CloudFormation automatically reverts or blocks changes; without change sets, updates apply immediately and can roll back only on failure.
  • ▸Confusing Patch Manager with State Manager or Automation; patching needs baselines plus maintenance windows, not just an association.
  • ▸Forgetting that NAT gateways live in public subnets and private subnet route tables must point to them for outbound internet access.

Practice set

Configuration Management and IaC questions

20 questions · select your answer, then reveal the explanation

A company uses AWS CloudFormation to deploy a multi-tier web application. The template includes a nested stack for the database layer. When updating the stack, the database stack fails with a 'CREATE_FAILED' status, but the parent stack continues updating other resources. What is the most likely cause and best practice to prevent this?

A DevOps engineer manages infrastructure using Terraform. The team needs to store secrets such as database passwords in a secure manner and reference them in Terraform configurations. They have configured AWS Secrets Manager. What is the recommended approach to reference secrets in Terraform without exposing them in state files?

A DevOps team is designing a CI/CD pipeline using AWS CodeBuild and CodePipeline. They want to use infrastructure as code to define the build environment. Which TWO options are valid approaches to define the build environment in CodeBuild?

Drag and drop the steps to set up an AWS Lambda function triggered by an S3 event.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

A DevOps team is using AWS CloudFormation to manage a multi-tier application. They want to ensure that when an update to the stack causes a resource replacement, the replacement occurs only after the new resource is fully created and tested. Which CloudFormation feature should they use?

A large enterprise uses AWS CloudFormation StackSets to deploy resources across multiple accounts and regions. They need to update a stack set that contains a custom resource backed by a Lambda function. The update changes the Lambda function code. What is the CORRECT approach to ensure the Lambda function is updated without manual intervention?

A company uses AWS CodeBuild to run tests as part of their CI/CD pipeline. They want to store build artifacts in an S3 bucket and ensure that only the latest successful build artifacts are retained. Which TWO actions should they take? (Choose TWO.)

A company uses AWS CloudFormation to manage its infrastructure. The security team requires that all S3 buckets have versioning enabled. A DevOps engineer needs to enforce this policy across all accounts in an AWS Organization. Which solution is MOST operationally efficient?

Question 9hardmultiple choice
Review the full subnetting walkthrough →

A company uses a central CloudFormation template to create VPCs with a standard CIDR block of 10.0.0.0/16. The template is used across multiple accounts and regions. The team needs to ensure that the VPC CIDR does not overlap with other VPCs in the same account. Which approach should the engineer take to dynamically assign a unique /16 subnet from a larger pool?

A company uses AWS OpsWorks for Chef to manage its configuration. The company is planning to migrate to AWS Systems Manager. Which AWS Systems Manager capabilities can replace OpsWorks Chef functionalities? (Choose THREE.)

A DevOps engineer creates the IAM policy shown in the exhibit to restrict EC2 instance types. However, users are still able to launch instances of type 't2.large'. What is the reason for this behavior?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": [
        "ec2:RunInstances"
      ],
      "Resource": "arn:aws:ec2:*:*:instance/*",
      "Condition": {
        "StringNotEquals": {
          "ec2:InstanceType": [
            "t2.micro",
            "t2.small",
            "t2.medium"
          ]
        }
      }
    },
    {
      "Effect": "Allow",
      "Action": [
        "ec2:RunInstances"
      ],
      "Resource": "*"
    }
  ]
}

A DevOps engineer runs the command shown in the exhibit to view stack events. The stack update failed. What is the most likely cause of the failure?

Network Topology
$ aws cloudformation describe-stack-eventsstack-name my-stackRefer to the exhibit."StackEvents": ["StackId": "arn:aws:cloudformation:us-east-1:123456789012:stack/my-stack/abcd1234-...","EventId": "Event-1","StackName": "my-stack","LogicalResourceId": "my-stack","PhysicalResourceId": "arn:aws:cloudformation:us-east-1:123456789012:stack/my-stack/abcd1234-...","ResourceType": "AWS::CloudFormation::Stack","Timestamp": "2023-01-15T10:00:00.000Z","ResourceStatus": "UPDATE_IN_PROGRESS","ResourceProperties": "{\"TemplateURL\":\"https://s3.amazonaws.com/my-bucket/template.yaml\"}","ResourceStatusReason": "User Initiated"},"EventId": "Event-2","LogicalResourceId": "MyLambdaFunction","PhysicalResourceId": "my-stack-MyLambdaFunction-ABC123","ResourceType": "AWS::Lambda::Function","Timestamp": "2023-01-15T10:01:00.000Z","ResourceStatusReason": "Resource creation initiated""EventId": "Event-3","Timestamp": "2023-01-15T10:02:00.000Z","ResourceStatus": "UPDATE_FAILED",Status Code: 400Error Code: InvalidParameterValueException...)"

A DevOps engineer is designing a CI/CD pipeline using AWS CodePipeline to deploy a serverless application. The application uses AWS Lambda functions and Amazon API Gateway. The engineer wants to implement a canary deployment strategy for the Lambda functions to reduce risk. Which AWS service or feature should be used to achieve this?

A team is using AWS CodeDeploy to deploy a web application to EC2 instances. They want to ensure that rollbacks occur automatically if the deployment fails. Which THREE configurations are necessary?

An administrator attaches the IAM policy shown in the exhibit to an IAM user. What is the effect on the user's ability to launch an EC2 instance in eu-west-1?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "ec2:*",
      "Resource": "*",
      "Condition": {
        "StringNotEquals": {
          "aws:RequestedRegion": ["us-east-1", "eu-west-1"]
        }
      }
    }
  ]
}

A DevOps engineer updated an EC2 instance's InstanceType in a CloudFormation stack and received the stack events shown in the exhibit. What is the most likely cause of the failure?

Network Topology
$ aws cloudformation describe-stack-eventsstack-name my-stackRefer to the exhibit."StackEvents": ["EventId": "...","StackName": "my-stack","LogicalResourceId": "my-stack","ResourceType": "AWS::CloudFormation::Stack","Timestamp": "2023-03-15T12:00:00.000Z","ResourceStatus": "UPDATE_ROLLBACK_IN_PROGRESS",},"LogicalResourceId": "MyEC2Instance","ResourceType": "AWS::EC2::Instance","Timestamp": "2023-03-15T11:59:00.000Z","ResourceStatus": "UPDATE_FAILED",

A team creates the CloudFormation template shown in the exhibit. What is a potential security concern with this configuration?

Exhibit

Refer to the exhibit.

AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: my-unique-bucket-123
      VersioningConfiguration:
        Status: Enabled
  MyBucketPolicy:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref MyBucket
      PolicyDocument:
        Statement:
          - Effect: Allow
            Action: s3:GetObject
            Resource: !Sub "${MyBucket.Arn}/*"
            Principal: "*"

A company uses AWS OpsWorks for configuration management. They want to ensure that a custom recipe runs on all instances in a layer every 30 minutes. What should they do?

A DevOps team is using AWS CloudFormation to manage infrastructure. They need to update a stack that includes an EC2 instance with a security group. The update requires changing a security group rule. Which method should the team use to perform this update with minimal disruption?

A company uses AWS OpsWorks for configuration management. They want to automate the installation of a custom agent on new EC2 instances. Which OpsWorks feature should they use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Configuration Management and IaC sessions

Start a Configuration Management and IaC only practice session

Every question in these sessions is drawn from the Configuration Management and IaC domain — nothing else.

Related practice questions

Related DOP-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the DOP-C02 exam test about Configuration Management and IaC?
Be able to read and write CloudFormation or CDK templates, use change sets for controlled deployments, and configure Systems Manager Patch Manager and State Manager for instance compliance. The single most important thing: know which resource and feature actually performs the required action, not just its general purpose.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Configuration Management and IaC questions in a focused session?
Yes — the session launcher on this page draws every question from the Configuration Management and IaC domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other DOP-C02 topics?
Use the topic links above to move to related areas, or go back to the DOP-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the DOP-C02 exam covers. They are not copied from any real exam or dump site.