Courseiva

Review and Approve CloudFormation Stack Updates Using Change Sets

A company is migrating to AWS and wants to use AWS CloudFormation to manage infrastructure as code. The DevOps team needs to ensure that stack updates are reviewed and approved before execution. Which feature should they use?

Quick Answer

The answer is AWS CloudFormation Change Sets, which allow you to review and approve CloudFormation stack updates before execution by generating a detailed summary of proposed infrastructure changes without actually applying them. This feature works by comparing the current stack template and parameters against the submitted update, producing a list of additions, modifications, and deletions that you can inspect and validate before committing. On the AWS Certified Solutions Architect Professional SAP-C02 exam, this concept tests your understanding of safe deployment practices and change management in infrastructure as code, often appearing as a distractor against StackSets (which manage multi-account deployments) or Drift Detection (which identifies post-deployment configuration differences). A common trap is confusing the ability to preview changes with the ability to detect existing drift, so remember that Change Sets are proactive and Drift Detection is reactive. Memory tip: think of a Change Set as a "preview before you play" button for your CloudFormation stacks.

⚠ Common exam trap

Many exam-takers confuse Drift Detection (which detects post-deployment configuration drift) with Change Sets (which preview intended changes before deployment), leading them to select Option A incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudFormation Change Sets

AWS CloudFormation Change Sets allow you to preview how proposed changes to a stack will impact your running resources before you apply them. This enables the DevOps team to review and approve stack updates by generating a summary of the changes (additions, modifications, deletions) without executing them immediately, meeting the requirement for a review-and-approval workflow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudFormation Drift Detection

    Why it's wrong here

    Drift detection only reports where deployed resources differ from the template; it neither previews nor gates a pending update. It is tempting for auditing configuration divergence in running stacks, but the requirement is human approval of proposed changes, which Change Sets supply by showing the change set before execution.

  • ✗

    AWS CloudFormation StackSets

    Why it's wrong here

    StackSets deploy one template across many accounts and Regions; they contain no review or approval mechanism for a single stack update. They are tempting for multi-account rollouts at scale, but the scenario needs a preview of pending changes, which Change Sets provide before the update is executed.

  • ✓

    AWS CloudFormation Change Sets

    Why this is correct

    CloudFormation change sets generate a preview of proposed resource modifications before execution, letting reviewers inspect additions, deletions and replacements. This directly satisfies the stem's requirement that stack updates be reviewed and approved prior to execution, since the change set must be explicitly executed after inspection.

  • ✗

    AWS CloudFormation Nested Stacks

    Why it's wrong here

    Nested stacks only decompose a template into reusable child stacks; they provide no approval gate before a stack update executes. They are tempting for modularising shared infrastructure across templates, but the requirement is a manual review step, which Change Sets deliver by previewing changes before execution.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's IT team uses AWS CloudFormation to deploy infrastructure. They want to enforce tagging standards across all stacks. Which approach should they use?

easy
  • A.Create an IAM policy that requires tags on all resources and attach it to all IAM users.
  • B.Configure CloudFormation to reject any stack that does not include tags.
  • ✓ C.Define stack-level tags in CloudFormation templates and use an SCP to deny creation of stacks without required tags.
  • D.Use AWS Config to detect resources without tags and automatically remediate using Systems Manager Automation.

Why C: AWS Organizations Service Control Policies (SCPs) can deny the creation of CloudFormation stacks that do not include required stack-level tags, while stack-level tags defined in the template propagate to all resources created by the stack. This combination enforces tagging standards across all stacks without relying on individual IAM user permissions or post-creation remediation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.