Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance. The administrator wants to ensure that if the stack is updated, the EC2 instance is not accidentally replaced if its properties change. The administrator wants the stack update to fail when a property change would require replacement. Which CloudFormation feature should the administrator use?

⚠ Common exam trap

Many exam-takers confuse UpdateReplacePolicy (which manages what happens to the old resource after replacement) with a mechanism to prevent replacement, but UpdateReplacePolicy does not block the update—it only controls the disposition of the replaced resource.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

StackPolicy

StackPolicy, is correct because a stack policy is a JSON document that defines which stack resources can be updated or replaced during a stack update. By setting a Deny effect on update actions for the EC2 instance, the administrator can prevent any property change that would cause replacement, causing the update to fail instead of replacing the instance. This directly meets the requirement to block accidental replacement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CreationPolicy

    Why it's wrong here

    CreationPolicy waits for a specified number of success signals from a resource before marking stack creation complete; it governs provisioning, not update behaviour. Stack policies are what cause an update to fail when a resource would be replaced. CreationPolicy suits resources needing readiness confirmation, such as Auto Scaling instances.

  • ✗

    DeletionPolicy

    Why it's wrong here

    DeletionPolicy governs what happens to a resource when its stack is deleted or removed, retaining or snapshotting it; it does not block updates. Stack policies are the feature that causes updates to fail when specified resources would be replaced. DeletionPolicy suits preserving data on teardown.

  • ✓

    StackPolicy

    Why this is correct

    StackPolicy allows you to define update permissions for stack resources, including denying update actions that would cause replacement, effectively causing the update to fail if such changes are attempted. This meets the requirement.

  • ✗

    UpdateReplacePolicy

    Why it's wrong here

    UpdateReplacePolicy is a CloudFormation attribute that controls the disposition of a resource when it is replaced during an update (e.g., retain or delete), but it does not prevent the replacement from occurring. Therefore, it does not cause the update to fail; it only specifies what happens to the old resource after replacement.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance and a security group. The administrator wants to ensure that when the stack is updated, the security group is not accidentally replaced if its properties change. The administrator wants to receive a failure if an update would require replacement of the security group. Which CloudFormation feature should the administrator use?

medium
  • A.Add a 'DeletionPolicy' attribute set to 'Retain' on the security group resource.
  • B.Add a 'CreationPolicy' attribute to the security group resource.
  • ✓ C.Define a stack policy that denies replacement of the security group resource.
  • D.Use an 'UpdatePolicy' attribute with 'AutoScalingReplacingUpdate' on the security group.

Why C: A stack policy can explicitly deny update actions that would replace a resource, such as the security group. By defining a stack policy with a Deny statement for the 'Replace' effect on the security group's logical resource ID, CloudFormation will fail the update if any property change triggers a replacement, preventing accidental deletion and recreation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.