DOP-C02 SDLC Automation Practice Question
Which TWO approaches can be used to automatically roll back a failed deployment in AWS CodeDeploy? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse CloudWatch Events rules with direct rollback triggers, but CloudWatch Events can only invoke actions like notifications or Lambda functions, not native CodeDeploy rollbacks, which require explicit configuration in the deployment group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the deployment group to automatically roll back when a deployment fails
AWS CodeDeploy allows you to configure a deployment group to automatically roll back a deployment when it fails. This is a native feature that can be enabled in the deployment group settings, ensuring that if a deployment fails (e.g., due to health check failures or script errors), CodeDeploy automatically reverts to the last known good revision without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a CloudWatch Events rule to trigger a rollback when a deployment fails
Why it's wrong here
A CloudWatch Events rule that merely detects a failed deployment does not perform a rollback; you would need a custom Lambda function to call CodeDeploy's RollbackDeployment API or redeploy the prior revision. CodeDeploy already provides native automatic rollback at the deployment-group level, so this approach adds a brittle external dependency and does not directly configure CodeDeploy to roll back. While it is possible to orchestrate this with custom code, it is not one of the two built-in approaches.
- ✗
Attach an IAM policy to the CodeDeploy service role that allows rollback actions
Why it's wrong here
Attaching an IAM policy that allows rollback-related actions to the CodeDeploy service role only grants the permissions required to initiate a rollback programmatically; it does not cause any automatic rollback behavior. Automatic rollback is a configuration of the deployment group itself, not a side effect of IAM authorization. The role must already have these permissions for automatic rollback to function, but the policy is a prerequisite, not the trigger.
- ✗
Specify a rollback revision in the AppSpec file
Why it's wrong here
The AppSpec file is used for defining file mappings and lifecycle event hooks (such as BeforeInstall and ApplicationStart) for a deployment; it contains no field for a 'rollback revision' or rollback configuration. When CodeDeploy performs an automatic rollback, it redeploys the last known good revision, which is determined from deployment history and the deployment group's settings, not from the AppSpec. Thus, specifying a rollback revision in the AppSpec is not a valid mechanism.
- ✓
Configure the deployment group to automatically roll back when a deployment fails
Why this is correct
Configuring the deployment group to automatically roll back when a deployment fails is a built-in CodeDeploy feature: you select this option in the deployment group's rollback configuration, and if the deployment fails (for example, due to a failed health check), CodeDeploy automatically redeploys the last successfully deployed revision. This is one of the two native automatic rollback triggers, and it requires no external services or custom code. It also logs the rollback as a new deployment event for auditability.
- ✓
Configure the deployment group to automatically roll back when a CloudWatch alarm is triggered
Why this is correct
Configuring the deployment group to automatically roll back when a CloudWatch alarm is triggered is the second native automatic rollback option. You associate an alarm (e.g., based on error rate or latency) with the deployment group; if the alarm enters ALARM state during or after a deployment, CodeDeploy triggers a rollback to the previous revision. This allows rollbacks based on operational health signals rather than only deployment failures, but it is still centralized in the deployment group's rollback configuration.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.