Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A company uses AWS Elastic Beanstalk to deploy a web application. After updating the environment configuration, the deployment fails and the environment health turns red. The SysOps administrator checks the logs and finds a permission error related to the EC2 instance profile. What should the administrator do to resolve the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the IAM instance profile associated with the environment to include the required permissions.

Elastic Beanstalk uses an IAM instance profile for the EC2 instances. The instance profile must have the necessary permissions to access resources like S3 buckets or DynamoDB tables. Updating the instance profile with the required permissions resolves the issue. Option A is wrong because rebuilding the environment from scratch using a saved configuration template does not address the underlying permission issue; it would only recreate the same problem. Option C is wrong because the security group controls network access, not IAM permissions; modifying it would not resolve the permission error. Option D is wrong because updating the application version does not fix permission issues; the application version itself does not grant or modify IAM permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rebuild the environment from scratch using a saved configuration template.

    Why it's wrong here

    Rebuilding the environment from a saved configuration template recreates the EC2 instances but reapplies the same environment configuration, including the same IAM instance profile. If that instance profile lacks the necessary permissions, the newly launched instances inherit the identical deficiency and still fail API calls. A rebuild only re-provisions infrastructure; it does not alter the IAM role or policy attached to the environment, so the original permission errors persist unchanged.

  • ✓

    Update the IAM instance profile associated with the environment to include the required permissions.

    Why this is correct

    Elastic Beanstalk environments use an IAM instance profile to grant permissions to the underlying EC2 instances. To resolve permission errors where the application cannot access required AWS services or resources, you must attach a policy that includes the necessary actions to the instance profile role. After updating the role, perform an environment update or restart so the running instances pick up the new permissions; this directly addresses the root cause because instance profile permissions govern what the application can do on AWS.

  • ✗

    Modify the security group attached to the environment to allow outbound traffic.

    Why it's wrong here

    Security groups act as a stateful virtual firewall at the network layer, controlling allowed inbound and outbound traffic by IP, port, and protocol. They have no effect on AWS IAM authorization; even if outbound traffic is opened to 0.0.0.0/0, an EC2 instance with an IAM role that lacks the required actions will still receive AccessDenied errors from AWS APIs. The problem is a permissions (authentication/authorization) issue, not a network connectivity issue, so adjusting security group rules cannot resolve the missing IAM policy.

  • ✗

    Update the application version to the latest build.

    Why it's wrong here

    Updating the application version to the latest build deploys different code, but the new version still runs on the same EC2 instances with the same IAM instance profile. Since IAM permissions are attached at the environment/infrastructure level rather than the application level, a code update cannot add the missing AWS API permissions. Unless the application code itself was changed to call a different AWS service, the same authorization failures will recur after the new version is deployed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.