SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator is troubleshooting a failed AWS CloudFormation stack update. The error message indicates that a resource failed to create due to insufficient IAM permissions. The administrator used a service role for CloudFormation. What should the administrator do to resolve the issue?
⚠ Common exam trap
SOA-C02 often tests whether candidates understand that CloudFormation uses the SERVICE ROLE's permissions, not the invoking user's — the trap is picking 'add permissions to my IAM user' out of habit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.
When CloudFormation assumes a service role to perform stack operations, all API calls made on behalf of the stack use that role's permissions — not the administrator's user permissions. The fix is to attach or update the IAM policy on the CloudFormation service role to grant the missing permissions (e.g., ec2:CreateInstance, s3:CreateBucket). This is the least-privilege, correct remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the required permissions to the administrator's IAM user.
Why it's wrong here
Adding the missing privileges to the administrator's IAM user will not resolve the failure because CloudFormation stack operations are executed with the permissions of the service role, not the calling user, once a service role is specified on the stack. While the user needs iam:PassRole to attach the service role to the stack, every Create/Update/Delete API call that CloudFormation makes is evaluated against the service role's policy, so the administrator's own IAM permissions are irrelevant to the resource-level operation that failed.
- ✗
Request a limit increase for IAM roles in the AWS account.
Why it's wrong here
A limit increase for IAM roles addresses service quotas, such as the maximum number of roles per account, but the error in this scenario is an authorization failure, not quota exhaustion. CloudFormation is attempting to perform an action that the service role's policy does not allow, so raising the role limit would have no effect on the denied API call. The failure message typically contains 'AccessDenied' or 'is not authorized to perform', which indicates a permissions issue rather than a resource limit.
- ✓
Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.
Why this is correct
The CloudFormation service role must have a permissions policy that explicitly grants the actions needed to create, update, and delete the stack's resources, because CloudFormation assumes this role to make those API calls on your behalf. Editing the role's IAM policy to include the required permissions, such as the relevant ec2:* or s3:* actions (or a narrowly scoped set), will allow the stack operation to proceed. This is the correct remedy because the service role's trust policy already permits CloudFormation to assume it; the missing piece is the authorization for the resource operations.
- ✗
Modify the resource's IAM policy to allow CloudFormation to create it.
Why it's wrong here
Modifying the resource's own IAM policy (for example, a bucket or KMS key policy) does not grant CloudFormation the ability to create that resource, because resource-based policies only control access to existing resources, not the Create* action CloudFormation calls during stack creation. To create a resource, CloudFormation needs the corresponding action in its service role's identity-based policy, such as s3:CreateBucket. Resource policies can affect subsequent access to the resource, but they are not a substitute for the service role's creation permissions, and many resource types do not even support resource-based policies.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.