Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Which TWO tools can be used to manage configuration drift detection for AWS resources? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse AWS Systems Manager Inventory (which collects instance-level software inventory) with configuration drift detection, or they mistakenly think AWS CloudTrail's API logging is sufficient to detect drift, when in fact drift detection requires comparing current state to a desired baseline, not just recording changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config continuously monitors and records AWS resource configurations and can detect changes against desired baselines, enabling drift detection through rules and compliance checks. AWS CloudFormation Drift Detection directly compares the current state of a stack's resources with the expected template-defined state to identify configuration drift. Both tools provide native mechanisms to detect when resources deviate from their intended configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Config

    Why this is correct

    AWS Config is the correct service for managing configuration drift because it continuously records and evaluates the configuration of AWS resources against desired baseline rules. When a resource's configuration changes from the recorded baseline, AWS Config flags it as noncompliant, providing a precise, rule-driven mechanism to detect drift. You can define custom or managed rules that represent your desired state, and AWS Config will produce a detailed compliance history and configuration timeline for every tracked resource, enabling automated remediation via Systems Manager Automation or Lambda.

  • ✗

    AWS Systems Manager Inventory

    Why it's wrong here

    AWS Systems Manager Inventory is not designed for configuration drift detection in the sense of comparing resource templates or AWS service configurations. Instead, it collects and stores metadata about the software installed on your managed instances, such as OS versions, application names, and patch levels. While this inventory data can be queried and used to identify software version mismatches, it does not evaluate resource configurations against desired AWS policies or templates, and it does not flag drift in infrastructure-as-code-defined resources.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is a guidance service that inspects your AWS account for best-practice recommendations across cost optimization, performance, security, and fault tolerance. It does not track the desired state of your resources or compare current versus expected configurations, so it cannot detect whether your deployed infrastructure has drifted from a CloudFormation template or a configuration baseline. Trusted Advisor provides point-in-time checks (e.g., unused security groups, underutilized instances) but lacks the continuous, rule-based evaluation and detailed compliance history that configuration drift management requires.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API activity in your account, providing an audit log of who made what changes and when. While CloudTrail logs are useful for post-incident forensics and can show the sequence of events that led to a configuration change, CloudTrail itself does not evaluate current resource configurations against a desired baseline, nor does it compare the actual state to an expected state. It is a monitoring and auditing tool, not a configuration drift detection mechanism; drift detection requires ongoing state comparison, not just event logging.

  • ✓

    AWS CloudFormation Drift Detection

    Why this is correct

    AWS CloudFormation Drift Detection is a valid tool for managing configuration drift because it compares the actual state of a CloudFormation stack's resources with the template-defined expected state. When you run drift detection, CloudFormation identifies any differences between the live configuration of a resource and the template specification, categorizing them as additions, deletions, or changes. However, note that drift detection is manual or requires scheduling, whereas AWS Config provides continuous, rule-based drift monitoring across all resources regardless of whether they were deployed via CloudFormation.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.