Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Which TWO are correct about using AWS CloudFormation to manage infrastructure across multiple AWS accounts? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

You can use AWS Organizations to centrally manage accounts and use StackSets with trusted access.

AWS Organizations can centrally manage accounts, and StackSets can be enabled with trusted access to deploy stacks across accounts. Option D is correct because AWS CloudFormation StackSets allow deploying stacks across multiple accounts. Option B is incorrect because CloudFormation cannot automatically create new AWS accounts. Option C is incorrect because nested stacks operate within a single stack and cannot deploy resources across different accounts from a single template. Option E is incorrect because cross-stack references only work within the same account and region.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    You can use AWS Organizations to centrally manage accounts and use StackSets with trusted access.

    Why this is correct

    Enabling trusted access for AWS CloudFormation in AWS Organizations allows StackSets to use the organization's structure (accounts and OUs) to automatically determine the set of target accounts. With service-managed permissions, any account added to the organization or an OU is automatically included in deployments, removing the need to manually maintain account lists. This centralization is a best practice for multi-account infrastructure management.

  • ✗

    CloudFormation can automatically create new AWS accounts using a template.

    Why it's wrong here

    CloudFormation templates are declarative documents that only manage resources that already exist within a single AWS account. There is no CloudFormation resource type that creates a new AWS account; account creation is performed by AWS Organizations using the CreateAccount API or during AWS Control Tower provisioning. Attempting to place account creation in a template would fail because the template has no valid resource type and no credentials to create the account outside the organization's management path.

  • ✗

    Nested stacks can be used to deploy resources in different accounts from a single template.

    Why it's wrong here

    Nested stacks are stacks declared inside a parent stack, enabling modular and reusable templates. All resources in the parent and nested stacks are provisioned within the same AWS account and AWS region; there is no field or parameter that changes the target account or region for a nested stack. Therefore, nested stacks cannot deploy resources across multiple accounts, and trying to use them for that purpose will either fail or require a different mechanism such as AWS CloudFormation StackSets.

  • ✓

    AWS CloudFormation StackSets can deploy stacks across multiple accounts.

    Why this is correct

    AWS CloudFormation StackSets is the native CloudFormation feature specifically designed to deploy identical stacks across multiple AWS accounts and regions. By creating a stack set and specifying target accounts (via self-managed permissions) or letting the organization control the target list (via service-managed permissions), you get consistent infrastructure across your entire organization from a single template. This is the correct way to achieve cross-account deployments with CloudFormation.

  • ✗

    You can use cross-stack references to share resources between accounts.

    Why it's wrong here

    Cross-stack references allow a stack in the same account and region to export an output (for example, a VPC ID) and another stack to import it using the Fn::ImportValue intrinsic function. The export namespace is per account and per region, so a stack in another account cannot import that exported value; the import would fail because the value does not exist in that account's namespace. For sharing resources across accounts, you should use AWS Resource Access Manager (RAM) or StackSets to provision synchronized resources, not CloudFormation cross-stack references.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.