Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A SysOps administrator is tasked with automating the creation of IAM roles and policies using AWS CloudFormation. The template includes an IAM role and a managed policy. The stack creation fails with the error 'Policy arn:aws:iam::123456789012:policy/MyManagedPolicy not found'. The policy is created in the same template. What is the MOST likely solution?

⚠ Common exam trap

A common mix-up: candidates assume CloudFormation automatically detects all dependencies based on resource references, but it only does so for direct 'Ref' or 'Fn::GetAtt' calls, not for ARN strings passed as parameters or hardcoded values, leading to a race condition where the role is created before the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a 'DependsOn' clause to the IAM role resource for the managed policy, and reference the policy ARN using the 'Ref' intrinsic function.

The error occurs because CloudFormation attempts to create the IAM role before the managed policy is fully created, even though both are defined in the same template. Adding a 'DependsOn' clause to the IAM role resource ensures that CloudFormation waits for the managed policy to be created first. Using the 'Ref' intrinsic function to reference the policy ARN is correct because 'Ref' for an AWS::IAM::ManagedPolicy returns the policy ARN, which is needed for the role's 'ManagedPolicyArns' property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a 'DependsOn' clause to the IAM role resource for the managed policy, and reference the policy ARN using the 'Ref' intrinsic function.

    Why this is correct

    In CloudFormation, a DependsOn attribute forces the IAM role resource to wait for the managed policy resource to be fully created before proceeding. The Ref intrinsic function on an IAM managed policy returns its ARN by default, so you can directly pass that ARN into the role's ManagedPolicyArns property. Without DependsOn, CloudFormation may attempt to attach the policy before it exists, causing the 'policy not found' error. This native dependency declaration is the simplest, most reliable fix.

  • ✗

    Remove the policy document from the template and create the policy separately.

    Why it's wrong here

    Removing the policy document from the template and creating it separately abandons the automation goal, since you then need a manual or out-of-band creation step. It also introduces an external dependency that makes the template non-portable and harder to manage in version control. CloudFormation natively supports managed policies and can resolve ordering within the same template, so separating the policy is unnecessary and undermines infrastructure-as-code best practices.

  • ✗

    Use a custom resource to create the policy before the role.

    Why it's wrong here

    Using a custom resource is inappropriate here because IAM policies are natively supported by CloudFormation. The 'policy not found' error indicates a dependency issue within the CloudFormation template itself, which is typically resolved using `DependsOn` or intrinsic function ordering for native resources. Custom resources are designed to extend CloudFormation's capabilities to manage AWS resources not natively supported, or to orchestrate external services, making them useful for integrating with third-party APIs or running bespoke scripts during stack lifecycle events.

  • ✗

    Create the IAM role in a separate stack.

    Why it's wrong here

    Creating the IAM role in a separate stack does not inherently solve the dependency problem; you would still need to reference the policy's ARN across stack boundaries, likely using Outputs and the Fn::ImportValue function. Moreover, CloudFormation does not guarantee that the policy stack completes before the role stack unless you add an explicit cross-stack dependency, so the same 'policy not found' error can recur. This approach adds administrative overhead and complexity without fixing the root cause of unordered resource creation.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.