SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS CloudFormation to manage infrastructure. The SysOps administrator needs to update a stack that contains a critical database. The update may require a replacement of the database resource. The administrator wants to review the changes before they are applied. What is the BEST way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the AWS CloudFormation create-change-set command and then review the changes before executing.
Creating a change set allows you to review all changes, including replacements, before executing them. Option A is incorrect because the '--no-fail-on-empty-changeset' flag does not provide a review. Option B is incorrect because a stack policy can protect resources but does not allow reviewing changes. Option D is incorrect because the drift detection feature detects drift, not planned changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the AWS CloudFormation update-stack command with the --no-fail-on-empty-changeset flag.
Why it's wrong here
The --no-fail-on-empty-changeset flag on the update-stack command only suppresses the failure that occurs when no changes are found; it does not alter the fact that update-stack executes changes immediately. This command compares your submitted template with the current stack and directly applies any differences, so there is no intermediate change set to review before the change is committed. Therefore, you never get the opportunity to inspect the exact resource-level modifications or replacement decisions before they are enacted.
- ✗
Apply a stack policy that prevents replacement of the database resource.
Why it's wrong here
A stack policy is a resource-level permission policy that controls which update, delete, or replacement operations are allowed on specific CloudFormation resources. While configuring it to deny replacement of the database resource would protect that resource from being swapped out during an update, the policy only acts as a guardrail that blocks or allows operations; it does not produce a preview or summary of the changes that would be made. Stack policies are evaluated when an update is attempted, but they never present a list of pending actions for you to approve or reject in advance.
- ✓
Use the AWS CloudFormation create-change-set command and then review the changes before executing.
Why this is correct
The create-change-set command constructs a change set that describes the modifications CloudFormation would make to the stack if the updated template were applied, without actually changing any resources. You can then use describe-change-set or the CloudFormation console to review every resource action (Add, Modify, Remove) including property details and whether a replacement will occur, before you decide to call execute-change-set. This two-phase approach is specifically designed to give you a safe, non-destructive preview of the update, which is exactly what the question requires.
- ✗
Use the AWS CloudFormation detect-stack-drift command to check for differences.
Why it's wrong here
The detect-stack-drift command compares the live state of your stack's resources against the expected configuration from the original template and declared parameters. It reveals manual modifications or external changes that have made the stack drift from its intended definition, but it does not simulate the effect of applying a new template version. Drift detection describes the current divergence between actual and declared state, whereas the requirement here is to preview prospective changes from an update, so it solves a different operational problem and cannot serve as a review mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.