SOA-C02 Reliability and Business Continuity Practice Question
A company uses AWS CloudFormation to deploy infrastructure. The SysOps administrator needs to ensure that if a stack update fails, the stack is automatically rolled back to the last known good state. Which TWO steps should the administrator take? (Choose two.)
⚠ Common exam trap
Many candidates confuse termination protection (which only prevents stack deletion) with rollback behavior, or they assume manual snapshots are part of CloudFormation's automatic rollback process, when in fact CloudFormation relies on resource-level reversal and service roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the stack to use a service role with permissions to perform rollback actions.
A service role grants CloudFormation the necessary IAM permissions to perform rollback actions on resources, such as deleting or reverting changes, even if the user who initiated the update lacks those permissions. This ensures that the stack can automatically return to its last known good state without manual intervention. Option C is correct because rollback triggers allow monitoring CloudWatch metrics; if a metric breaches the specified threshold, CloudFormation automatically rolls back the stack, providing an additional safeguard. Option E is incorrect because a stack policy only prevents updates to protected resources but does not enable or automate rollback on failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a manual snapshot of the database before each update.
Why it's wrong here
While taking a manual DB snapshot is a good backup best practice, CloudFormation's automated rollback does not use or restore snapshots that you create manually. Rollback of a database resource is accomplished by reverting the resource's desired state to the previous template, not by importing a separate snapshot; if the database can't be reverted, you'd have to restore the snapshot personally. Thus, snapshots don't enable automatic rollback.
- ✓
Configure the stack to use a service role with permissions to perform rollback actions.
Why this is correct
CloudFormation uses a service role to make API calls when creating, updating, or deleting stack resources. On a failed update, the service must be able to reverse changes—delete newly created resources, revert modifications, and in some cases re-create previous resources—so the role needs explicit permissions for those rollback actions. Without those permissions, rollback can stall, leaving the stack in UPDATE_ROLLBACK_FAILED.
- ✓
Use rollback triggers to monitor CloudWatch metrics and automatically roll back the stack if a metric breache.
Why this is correct
Rollback triggers let you associate CloudWatch alarms with a stack; during an update, CloudFormation monitors the alarm state and if it transitions to ALARM—typically due to application-level health checks—it automatically begins a rollback. This is an explicit automated rollback feature designed around operational health, not just resource provisioning errors. It complements the standard rollback that occurs when template or resource creation fails.
- ✗
Enable termination protection on the stack.
Why it's wrong here
Termination protection is a stack-level attribute that only prevents a DeleteStack API call from removing the entire stack. It has no effect on the update rollback workflow, because rollback occurs within the same stack as a replacement of resources to their prior configuration. Therefore, enabling it cannot ensure that a failed update is automatically reversed.
- ✗
Define a stack policy that prevents updates to the database resources.
Why it's wrong here
A stack policy is an access-control document that limits which resources CloudFormation may update or replace during an update. Restricting updates to the database prevents the update from modifying the DB at all, but it neither detects a failure nor restores previous state; if the update fails elsewhere, the policy does nothing to roll back. It's a preventive safeguard, not a rollback mechanism, and could actually block a legitimate update.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is using AWS CloudFormation to deploy infrastructure. The SysOps administrator needs to ensure that if a stack update fails, the stack automatically rolls back to the last known good state. Which stack update option should be configured?
medium- A.Disable rollback
- B.Change sets
- ✓ C.Rollback on failure
- D.Stack policy
Why C: CloudFormation's 'Rollback on failure' option, enabled by default, automatically reverts a stack to its last known good state if a stack update fails. This ensures that failed updates do not leave the infrastructure in an inconsistent or partially deployed state, maintaining reliability and business continuity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.