SOA-C02 Deployment, Provisioning, and Automation Practice Question
A company uses AWS CodeDeploy to deploy an application to Amazon EC2 instances. The SysOps administrator wants to implement a deployment strategy that minimizes risk by deploying the new version to a small number of instances first, verifying that the deployment is successful, and then deploying to the remaining instances. If the initial deployment fails, the process should stop and roll back. Which CodeDeploy deployment configuration should be used?
⚠ Common exam trap
Many candidates confuse CodeDeployDefault.Canary10Percent10Minutes (a traffic-shifting configuration for Lambda/ECS) with a linear EC2 deployment strategy, or they mistakenly think HalfAtATime provides sufficient risk mitigation when the requirement explicitly calls for deploying to a 'small number' first and stopping on failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CodeDeployDefault.OneAtATime
CodeDeployDefault.OneAtATime, is correct because it deploys the new application revision to one instance at a time, checking for success before proceeding to the next. If any deployment step fails, the process stops and automatically rolls back, minimizing risk by limiting the blast radius of a bad deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CodeDeployDefault.AllAtOnce
Why it's wrong here
CodeDeployDefault.AllAtOnce is a deployment configuration that targets every EC2 instance in the deployment group at the same time, causing all instances to stop serving traffic and install the new revision simultaneously. This approach offers no staged verification or health check gating between batches, so if the new revision has a defect, the entire fleet can be impacted at once, potentially causing a full outage. It is the least cautious option and fails the requirement to first test on a very small number of instances.
- ✗
CodeDeployDefault.HalfAtATime
Why it's wrong here
HalfAtATime deploys to half of the instances first, then to the remaining half. While it verifies the first half before proceeding, the first batch could be large depending on group size, which may be riskier than a very small batch.
- ✓
CodeDeployDefault.OneAtATime
Why this is correct
OneAtATime deploys to a single instance at a time, verifies that it is healthy, and then proceeds to the next. This is the most cautious approach and matches the requirement of deploying to a small number (one) first, then continuing to the rest.
- ✗
CodeDeployDefault.Canary10Percent10Minutes
Why it's wrong here
CodeDeployDefault.Canary10Percent10Minutes is a traffic-shifting configuration used for AWS Lambda and Amazon ECS deployments, not for Amazon EC2 in-place deployments. In-place deployments for EC2 are limited to instance-based configurations (AllAtOnce, HalfAtATime, OneAtATime); a canary configuration that shifts traffic percentages over time is simply not valid in this context. Selecting it would either cause a validation error or require an unsupported deployment style, so it cannot satisfy the requirement of deploying to a small number of EC2 instances first.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.