SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The error message indicates that an IAM role creation failed because the role already exists. The administrator wants to ensure the stack creation can proceed without manual intervention. What should the administrator do?
⚠ Common exam trap
Test-takers frequently confuse deletion policies (which affect resource lifecycle after deletion) with creation-time conflicts, or mistakenly think stack policies can block resource creation when they only govern updates and deletions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the template to use a unique name for the IAM role.
The error indicates a naming conflict: the IAM role name in the template already exists in the account. By modifying the template to use a unique name (e.g., appending a random string or using `AWS::NoValue` with `Fn::Sub`), CloudFormation can create the role without conflicting with the existing resource. This approach avoids manual intervention and allows the stack creation to proceed automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Modify the template to use a unique name for the IAM role.
Why this is correct
CloudFormation IAM roles with an explicit RoleName property must be unique within the account and Region. If a role with that name already exists, stack creation fails with a resource conflict error. By appending the stack name or a random suffix to the RoleName, you ensure uniqueness without manual cleanup; this is the standard automated fix and aligns with AWS best practices for avoiding namespace collisions.
- ✗
Use the 'Retain' deletion policy on the IAM role resource.
Why it's wrong here
The DeletionPolicy attribute, including the 'Retain' value, only instructs CloudFormation to preserve a resource when its parent stack is deleted. It has no effect during stack creation and cannot prevent the service from failing when it tries to create an IAM role that already exists. Applying Retain here would be misleading and could leave orphaned roles after stack deletion, but it does nothing to resolve the current naming conflict.
- ✗
Manually delete the existing IAM role and retry the stack creation.
Why it's wrong here
Manually deleting the pre-existing IAM role might unblock stack creation, but it is not an automated or safe solution. The role may be in use by other applications, and deleting it manually could cause outages or require excessive IAM permissions. Furthermore, this approach sidesteps the root cause: the template explicitly declares a fixed, non-unique name. A proper fix should make the template self-sufficient by generating a unique name rather than requiring an operator to alter the environment.
- ✗
Use a stack policy to prevent the creation of the IAM role.
Why it's wrong here
Stack policies are JSON statements that control permitted updates and deletions on existing stack resources during a stack update operation. They are completely ignored during the initial creation of a stack, so they cannot prevent CloudFormation from attempting to create a resource with a conflicting name. Even if applied, a stack policy would not exempt CloudFormation from the IAM service's uniqueness constraint; it only governs modification actions, not creation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.