Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED. Which two actions are appropriate next steps? (Choose 2.)

⚠ Common exam trap

A common mix-up: candidates think deleting the service role or renaming the stack are valid recovery actions, but AWS CloudFormation requires explicit rollback continuation or manual intervention via the continue-update-rollback API, not workarounds that break IAM or naming conventions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review stack events to identify the resource that blocked rollback.

When a CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED, the stack events provide detailed error messages for each resource that failed during rollback. Reviewing these events is essential to identify the specific resource that blocked the rollback, such as a resource that could not be deleted or updated due to permissions, dependencies, or configuration issues. This diagnosis is the first step before attempting a continue-update-rollback operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Review stack events to identify the resource that blocked rollback.

    Why this is correct

    Stack events expose the precise CloudFormation status of each logical resource during the failed update and subsequent rollback attempt, including the exact API error that caused the rollback to stall—for example, an EC2 security group dependency that could not be evaluated. By reviewing the most recent event entries, you can pinpoint whether a resource is stuck in CLEANUP_IN_PROGRESS or UPDATE_ROLLBACK_IN_PROGRESS and read the underlying failure message. This diagnosis determines whether you can safely run continue-update-rollback without skipping resources.

  • ✓

    Use continue-update-rollback after resolving the underlying issue or specifying resources to skip when appropriate.

    Why this is correct

    The continue-update-rollback API operation is the official recovery path when a stack reaches UPDATE_ROLLBACK_FAILED, but it will fail again unless the root cause—such as a missing IAM permission or a deleted resource—is fixed first. You can optionally pass --resources-to-skip to instruct CloudFormation to ignore a resource that cannot be rolled back, provided that resource is not critical to the stack's stable state. This is a targeted remediation, distinct from simply reviewing events, because it actively moves the stack back toward a usable status.

  • ✗

    Delete the CloudFormation service role from IAM.

    Why it's wrong here

    Deleting the IAM role that CloudFormation assumed to perform the update removes the very permissions needed to finish rollback operations, because CloudFormation uses the role to call the underlying APIs on each resource. Without that role, the stack becomes permanently stuck in UPDATE_ROLLBACK_FAILED, and you cannot use continue-update-rollback because the API calls to revert resource changes will be denied. This action worsens the situation; the correct approach is to repair the role's policy or dependencies rather than delete it.

  • ✗

    Rename the stack to force rollback completion.

    Why it's wrong here

    A CloudFormation stack name is an immutable identifier tied to the stack's resources and lifecycle; there is no supported operation to rename a stack, and changing its name would not affect any in-progress operation or the stack's status. Attempting to 'rename' by creating a new stack with the same name is impossible until the original is deleted, and deletion also fails because the stack is in UPDATE_ROLLBACK_FAILED. This option does not trigger rollback completion; it only creates confusion about which stack is being managed.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using AWS CloudFormation to manage infrastructure. A recent stack update failed, and the SysOps administrator needs to roll back to the previous known good state. However, the stack is in UPDATE_ROLLBACK_FAILED state. What should the administrator do to recover the stack?

hard
  • ✓ A.Use the ContinueUpdateRollback API or AWS Management Console to resume the rollback after addressing the failure cause
  • B.Delete the stack and recreate it from the previous template
  • C.Contact AWS Support to enable automatic rollback recovery
  • D.Execute another stack update with the same parameters to overwrite the failed state

Why A: When a CloudFormation stack enters UPDATE_ROLLBACK_FAILED, the rollback could not complete because a resource could not be returned to its previous state. The administrator must first fix the underlying resource issue (e.g., a deleted resource, a permission problem, or a resource that cannot be reverted), then invoke ContinueUpdateRollback via the console, CLI, or API to resume the rollback from where it stopped. This preserves the stack and its resources rather than destroying them.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.