A company uses AWS CloudFormation to deploy its infrastructure. The SysOps administrator needs to be notified when a stack creation fails. Which solution meets this requirement with the LEAST effort?
The NotificationARNs parameter is a native CloudFormation feature that accepts one or more Amazon SNS topic ARNs, causing CloudFormation to publish all stack lifecycle events—including CREATE_FAILED, ROLLBACK_COMPLETE, and resource-level failures—to the topic. This is the built-in, real-time mechanism designed exactly for this scenario, requiring no custom code, polling, or metric configuration. Simply specify the SNS topic ARN when creating or updating the stack, and ensure the topic policy trusts CloudFormation's publishing role.
Why this answer
CloudFormation natively supports specifying an SNS topic in the 'NotificationARNs' parameter, which automatically sends notifications on stack events such as creation failure. This requires no additional infrastructure, scripting, or monitoring setup, making it the least-effort solution.
Exam trap
The trap here is that candidates often overthink and choose CloudWatch alarms or CloudTrail, not realizing that CloudFormation's built-in SNS notification parameter provides a zero-configuration, event-driven solution for stack failure alerts.
How to eliminate wrong answers
Option A is wrong because CloudWatch cannot directly alarm on CloudFormation stack status; CloudWatch alarms are designed for metrics (e.g., EC2 CPU utilization) and not for CloudFormation stack state changes. Option B is wrong because CloudTrail logs API calls but does not trigger SNS notifications directly; you would need additional services like EventBridge to route the event to SNS, adding complexity. Option D is wrong because writing a custom script to poll the CloudFormation API every minute introduces unnecessary overhead, latency, and maintenance effort, contradicting the 'least effort' requirement.