Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack update. The error message indicates that a resource failed to create due to insufficient IAM permissions. The administrator used a service role for CloudFormation. What should the administrator do to resolve the issue?

⚠ Common exam trap

SOA-C02 often tests whether candidates understand that CloudFormation uses the SERVICE ROLE's permissions, not the invoking user's — the trap is picking 'add permissions to my IAM user' out of habit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.

When CloudFormation assumes a service role to perform stack operations, all API calls made on behalf of the stack use that role's permissions — not the administrator's user permissions. The fix is to attach or update the IAM policy on the CloudFormation service role to grant the missing permissions (e.g., ec2:CreateInstance, s3:CreateBucket). This is the least-privilege, correct remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the required permissions to the administrator's IAM user.

    Why it's wrong here

    Adding the missing privileges to the administrator's IAM user will not resolve the failure because CloudFormation stack operations are executed with the permissions of the service role, not the calling user, once a service role is specified on the stack. While the user needs iam:PassRole to attach the service role to the stack, every Create/Update/Delete API call that CloudFormation makes is evaluated against the service role's policy, so the administrator's own IAM permissions are irrelevant to the resource-level operation that failed.

  • ✗

    Request a limit increase for IAM roles in the AWS account.

    Why it's wrong here

    A limit increase for IAM roles addresses service quotas, such as the maximum number of roles per account, but the error in this scenario is an authorization failure, not quota exhaustion. CloudFormation is attempting to perform an action that the service role's policy does not allow, so raising the role limit would have no effect on the denied API call. The failure message typically contains 'AccessDenied' or 'is not authorized to perform', which indicates a permissions issue rather than a resource limit.

  • ✓

    Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.

    Why this is correct

    The CloudFormation service role must have a permissions policy that explicitly grants the actions needed to create, update, and delete the stack's resources, because CloudFormation assumes this role to make those API calls on your behalf. Editing the role's IAM policy to include the required permissions, such as the relevant ec2:* or s3:* actions (or a narrowly scoped set), will allow the stack operation to proceed. This is the correct remedy because the service role's trust policy already permits CloudFormation to assume it; the missing piece is the authorization for the resource operations.

  • ✗

    Modify the resource's IAM policy to allow CloudFormation to create it.

    Why it's wrong here

    Modifying the resource's own IAM policy (for example, a bucket or KMS key policy) does not grant CloudFormation the ability to create that resource, because resource-based policies only control access to existing resources, not the Create* action CloudFormation calls during stack creation. To create a resource, CloudFormation needs the corresponding action in its service role's identity-based policy, such as s3:CreateBucket. Resource policies can affect subsequent access to the resource, but they are not a substitute for the service role's creation permissions, and many resource types do not even support resource-based policies.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.