SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS CloudFormation to deploy a multi-tier application. The template uses nested stacks. One of the nested stacks creates an Auto Scaling group. The administrator wants to update the Auto Scaling group's launch configuration to use a new AMI ID. The AMI ID is stored in AWS Systems Manager Parameter Store. The administrator wants to ensure that the stack update automatically uses the latest AMI ID value from Parameter Store. What should the administrator do?
⚠ Common exam trap
Many exam-takers think a CloudFormation parameter with a default value or a mapping can achieve dynamic updates, but both are static unless manually changed, whereas dynamic references automatically pull the latest value from Parameter Store during stack operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a CloudFormation dynamic reference to the parameter store in the template.
CloudFormation dynamic references for Systems Manager Parameter Store (using the `{{resolve:ssm:/parameter-name}}` syntax) automatically resolve the latest parameter value at stack creation or update time. This ensures that the launch configuration always uses the current AMI ID from Parameter Store without manual intervention or hardcoding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a CloudFormation dynamic reference to the parameter store in the template.
Why this is correct
A dynamic reference using {{resolve:ssm:parameter-name}} is resolved by CloudFormation at the time a stack operation is performed, not when the template is authored. This means that when you update the stack after the Systems Manager Parameter Store value changes, CloudFormation automatically retrieves the current AMI ID and uses it for resource creation or replacement. It is the only option that inherently satisfies the requirement to automatically adopt the latest AMI ID without editing the template or providing manual input.
- ✗
Use a CloudFormation mapping to map the AMI ID.
Why it's wrong here
A mapping stores key-value pairs as static literals inside the CloudFormation template itself. Although you can select an AMI ID based on a key such as an AWS region or environment, the mapping values are fixed at template authoring time; they cannot call the Systems Manager Parameter Store or read a live parameter value. To use a new AMI ID, you would have to edit the mapping in the template and perform a stack update, which does not meet the 'automatically uses the latest' requirement.
- ✗
Use a custom resource to call Systems Manager to retrieve the AMI ID.
Why it's wrong here
Using a custom resource to fetch the AMI ID is insufficient because it typically executes only when the custom resource itself is created, updated, or replaced. A change to the Parameter Store value alone would not automatically trigger the custom resource to re-evaluate and provide the new AMI ID during a subsequent stack update, failing the "automatically uses the latest" requirement. Custom resources are valuable for extending CloudFormation's functionality, such as integrating with unsupported services or performing complex logic and transformations during deployment where native capabilities are lacking.
- ✗
Use a CloudFormation parameter with a default value that matches the AMI ID.
Why it's wrong here
A parameter with a default value is baked into the template, and CloudFormation treats that default as a fixed value unless a different value is supplied at stack creation or update time. Changing the default in the template does not affect an existing stack until you explicitly update the stack with the new parameter value. Because the Parameter Store value is never consulted, the stack will continue using the old AMI ID even after the parameter changes.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.