Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A company is using AWS CloudFormation to deploy a multi-tier web application. After updating the stack template, the update fails with a stack creation rollback in progress error. The SysOps administrator needs to identify the specific resource that caused the failure. What is the MOST efficient way to accomplish this?

⚠ Common exam trap

SOA-C02 often tests the confusion between change sets (which preview proposed changes) and stack events (which record actual execution results) — candidates pick describe-change-set thinking it shows failures, but it only shows what was planned.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the AWS CLI command aws cloudformation describe-stack-events --stack-name <stack-name> and review the resource status reason.

The describe-stack-events command returns a chronological list of every stack event, including each resource's status and the 'ResourceStatusReason' field that contains the exact error message from the failed resource. This is the fastest, most direct way to pinpoint which resource caused the rollback without digging through unrelated logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the AWS Management Console to view the stack status and check the stack policy.

    Why it's wrong here

    Viewing the stack status in the AWS Management Console provides only a high-level aggregate state, such as UPDATE_ROLLBACK_COMPLETE, and does not expose per-resource failure reasons. Checking the stack policy is unrelated to troubleshooting failed updates because the stack policy controls which resources can be updated, not how failures are reported. The console's Events tab would show the same detailed status reason information, but simply looking at the status and policy will not reveal why a specific resource failed.

  • ✗

    Use the aws cloudformation describe-change-set command to review the proposed changes.

    Why it's wrong here

    The aws cloudformation describe-change-set command returns a preview of the changes CloudFormation plans to make to the stack, such as which resources will be modified, replaced, or left unchanged. It does not execute the update and therefore contains no information about runtime failures, resource status transitions, or the actual status reason that occurred during a failed update. This command is useful for validating a changeset before execution, not for post-update troubleshooting.

  • ✗

    Check the CloudTrail logs for the UpdateStack API call to see the error message.

    Why it's wrong here

    CloudTrail logs for the UpdateStack API call capture the request parameters, the IAM principal who invoked the call, and the response elements, but CloudTrail does not record the granular per-resource status reasons that CloudFormation generates during resource provisioning. Those reasons are emitted as stack events, which include fields like ResourceStatus and ResourceStatusReason for each logical resource. Relying on CloudTrail alone would only tell you that an UpdateStack request was made, not why a particular resource failed to update.

  • ✓

    Run the AWS CLI command aws cloudformation describe-stack-events --stack-name <stack-name> and review the resource status reason.

    Why this is correct

    Running aws cloudformation describe-stack-events --stack-name <stack-name> retrieves every event in the stack's lifecycle, including the most recent update attempt. Each event includes the LogicalResourceId, ResourceStatus (e.g., UPDATE_FAILED), and the ResourceStatusReason field, which contains the specific error message from the underlying AWS service that caused the failure. Reviewing the events in reverse chronological order lets you pinpoint exactly which resource failed and why, making this the definitive troubleshooting command for failed CloudFormation operations.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.