Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Which TWO approaches can be used to automate the creation of an AWS CloudFormation stack that includes IAM resources? (Select TWO.)

⚠ Common exam trap

Candidates often confuse IAM permissions (like `IAMFullAccess`) with the CloudFormation capability acknowledgment, thinking that having the right IAM policy alone is sufficient to create IAM resources in a stack, when in fact the `CAPABILITY_IAM` or `CAPABILITY_NAMED_IAM` flag must be explicitly set in the API call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an AWS Lambda function to call the CreateStack API with the capabilities parameter set to 'CAPABILITY_IAM'.

When a CloudFormation stack includes IAM resources, you must explicitly acknowledge that the stack may create IAM entities. An AWS Lambda function calling the CreateStack API with the `capabilities` parameter set to `CAPABILITY_IAM` satisfies this requirement. Option E is correct because the AWS CLI `create-stack` command with the `--capabilities CAPABILITY_IAM` parameter also provides the required acknowledgment, allowing the stack to be created successfully.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the CloudFormation template in an Amazon S3 bucket and use the 'aws cloudformation deploy' command.

    Why it's wrong here

    Storing the template in Amazon S3 is a common practice to handle large templates, but it does not address CloudFormation's requirement to acknowledge IAM resource creation. The 'aws cloudformation deploy' command also requires the '--capabilities' parameter; without specifying CAPABILITY_IAM or CAPABILITY_NAMED_IAM, the deployment will fail with an insufficient capabilities error. Thus, S3 storage alone cannot automate the approval process for IAM resources.

  • ✗

    Set the 'CAPABILITY_NAMED_IAM' capability when calling the CreateStack API.

    Why it's wrong here

    CAPABILITY_NAMED_IAM is a specialized acknowledgement used only when the template creates IAM resources with custom names, such as a fixed role name. For general IAM resources that CloudFormation names automatically, CAPABILITY_IAM is the required and sufficient capability. Setting CAPABILITY_NAMED_IAM without reason is unnecessary and doesn't correctly map to the generic IAM resource scenario, so this approach is incorrect.

  • ✗

    Attach the AWS managed policy 'IAMFullAccess' to the IAM user or role executing the stack creation.

    Why it's wrong here

    Attaching IAMFullAccess grants the user or role the necessary IAM permissions, but CloudFormation enforces an independent administrative check through the capabilities parameter. Even an administrator with full access must explicitly pass CAPABILITY_IAM or CAPABILITY_NAMED_IAM when creating a stack that contains IAM resources; otherwise, the CreateStack API call fails. Thus, IAMFullAccess alone is insufficient to automate the stack creation.

  • ✓

    Use an AWS Lambda function to call the CreateStack API with the capabilities parameter set to 'CAPABILITY_IAM'.

    Why this is correct

    An AWS Lambda function can programmatically call the CreateStack API and include 'CAPABILITY_IAM' in the Capabilities list, satisfying CloudFormation's acknowledgement requirement. This is a valid automation method because the Lambda handler can pass the parameter directly in the SDK request, and the function can be triggered by various events. The Lambda execution role must have permission to create stacks and the necessary IAM resources.

  • ✓

    Use the AWS CLI command 'aws cloudformation create-stack' with the '--capabilities CAPABILITY_IAM' parameter.

    Why this is correct

    The AWS CLI command 'aws cloudformation create-stack' with '--capabilities CAPABILITY_IAM' is a correct way to automate stack creation because it explicitly acknowledges that the template may create IAM resources. This flag tells CloudFormation that you are aware of the IAM resource additions and accepts the associated security implications. This command can be invoked in scripts or pipelines, making it a practical automation approach.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.