SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator is automating the creation of Amazon RDS instances using AWS CloudFormation. The template includes a DBInstance resource with a DBSubnetGroupName property referencing a subnet group created in the same template. The stack creation fails with the error 'DBSubnetGroup not found'. What is the MOST likely reason?
⚠ Common exam trap
Many exam-takers assume CloudFormation automatically resolves all dependencies based on property references, but it only does so for intrinsic function references (Ref, Fn::GetAtt), not for plain string values like DBSubnetGroupName.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A DependsOn clause is missing between the DBInstance and the DBSubnetGroup.
In AWS CloudFormation, resource creation order is not guaranteed unless explicitly defined. When a DBInstance resource references a DBSubnetGroup by name, CloudFormation may attempt to create the DBInstance before the DBSubnetGroup is fully created, resulting in a 'DBSubnetGroup not found' error. Adding a DependsOn clause to the DBInstance resource ensures the DBSubnetGroup is created first, resolving the dependency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPC ID is incorrect or does not exist.
Why it's wrong here
If the VPC ID were incorrect or nonexistent, CloudFormation would fail earlier when validating the subnet IDs or creating the DBSubnetGroup, producing an error such as 'The specified VPC ID does not exist' or 'Subnets are not in the requested VPC.' The DBSubnetGroup references subnets directly, and the DBInstance implicitly uses the VPC through that subnet group. Therefore, an invalid VPC would trigger a different, more fundamental infrastructure validation error, not the observed dependency-related failure about the DBSubnetGroup being missing.
- ✗
The DBSubnetGroup is not associated with a public subnet.
Why it's wrong here
RDS does not require a DBSubnetGroup to include public subnets; in fact, production databases are typically placed in private subnets for security and to avoid direct internet exposure. A DBSubnetGroup simply designates which subnets in a VPC are eligible for RDS to place instances across multiple Availability Zones. The absence of a public subnet would affect whether the DB instance receives a public IP address or is reachable from the internet, but it would not cause CloudFormation to report that the DBSubnetGroup does not exist. The error described in the scenario is a resource ordering issue, not a subnet visibility or route table configuration issue.
- ✓
A DependsOn clause is missing between the DBInstance and the DBSubnetGroup.
Why this is correct
CloudFormation does not automatically create an intrinsic dependency between a DBInstance and a DBSubnetGroup when the DBSubnetGroup is referenced by its name string rather than through the Ref function. Since the DBSubnetGroupName property in an RDS DBInstance expects a string, passing a literal name or a parameter does not establish a resource dependency, so CloudFormation may attempt to create the DBInstance before the DBSubnetGroup exists. This results in an error such as 'The specified DB Subnet Group does not exist' or 'DBSubnetGroup not found.' Adding an explicit DependsOn attribute to the DBInstance forces CloudFormation to wait until the DBSubnetGroup has been successfully created, making the creation order deterministic and resolving the failure.
- ✗
The DBSubnetGroup is defined in a different CloudFormation stack.
Why it's wrong here
If the DBSubnetGroup were defined in a different CloudFormation stack, you would need to use cross-stack references such as an exported output value and an ImportValue function to fetch the subnet group name into the DBInstance stack. However, the scenario explicitly states that the resources are in the same template, so a cross-stack reference issue is irrelevant here. Even in a cross-stack scenario, the failure mode would likely be an unresolved import or missing export value, which is a different error from the race condition described. The problem in this question is specifically the lack of an explicit dependency within the same template, not a cross-stack boundary issue.
Visual reference
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.