DOP-C02 SDLC Automation Practice Question
Which TWO criteria must be met for an AWS CloudFormation stack update to be successful? (Choose 2.)
⚠ Common exam trap
Candidates often confuse 'stack must be in a steady state' (a common misconception) with the actual requirement that the stack must be in a state that allows updates, such as CREATE_COMPLETE or UPDATE_COMPLETE, not necessarily without any prior failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The update template must be valid and must not contain any syntax errors.
AWS CloudFormation validates the template syntax and structure before initiating any stack update. If the template contains invalid JSON or YAML, references nonexistent resources, or violates intrinsic function rules, the update request is rejected immediately. This validation ensures that only syntactically correct templates proceed to the update operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The update template must be valid and must not contain any syntax errors.
Why this is correct
CloudFormation performs template validation before any update action is taken, checking for well-formed JSON/YAML, resolving intrinsic functions, validating resource types and required properties. An invalid template will cause the UpdateStack API call to fail immediately with a ValidationError, leaving the stack's current status unchanged. This is a hard precondition that every direct update must satisfy.
- ✗
The stack must be in a steady state with no previous failed updates.
Why it's wrong here
A previous failed update does not permanently lock a stack out of future updates. As long as the stack has reached a terminal state after rollback (e.g., UPDATE_ROLLBACK_COMPLETE) or a subsequent update succeeded, you can issue a new update. CloudFormation cares about the stack's current lifecycle status, not its history of past failures, so this option incorrectly imposes a stricter requirement than the service enforces.
- ✓
The stack must be in a state that allows updates (e.g., CREATE_COMPLETE, UPDATE_COMPLETE).
Why this is correct
The stack must currently be in a lifecycle state from which an update operation is allowed, such as CREATE_COMPLETE, UPDATE_COMPLETE, or UPDATE_ROLLBACK_COMPLETE. Transient states like CREATE_IN_PROGRESS, UPDATE_IN_PROGRESS, or DELETE_IN_PROGRESS will cause the update request to be rejected because CloudFormation cannot safely modify resources while another operation is still mutating them. This is a fundamental concurrency guard, not a check on historical events.
- ✗
A change set must be created and executed before the update.
Why it's wrong here
Change sets are an optional preview mechanism, not a required precursor to updating a stack. You can invoke UpdateStack directly with a new template and CloudFormation will immediately compute the changes, obtain any necessary IAM capabilities, and perform the update. The only time a change set is necessary is if you want to manually review and approve a proposed change before executing it, so this statement falsely elevates an optional workflow to a hard prerequisite.
- ✗
The stack must have no drift detected.
Why it's wrong here
Stack drift indicates that the actual live resource configuration differs from the template's expected configuration, but CloudFormation will still allow and perform updates on drifted stacks. Drift detection is a separate audit feature used for governance and compliance, not a gate for update operations. An update will generally overwrite drifted settings with the newly specified template values, but drift does not block the update request itself.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.