A DevOps engineer wants to automate the creation of an Amazon EC2 instance with a specific security group and IAM role. Which AWS service should be used to define the infrastructure as code?
CloudFormation is the native AWS infrastructure-as-code service: you define resources in a JSON or YAML template, and the service provisions, updates, and deletes them as a stack with order-aware dependencies and automatic rollback on failures. It supports almost every AWS resource and allows drift detection to compare actual configuration to template state. This exactly matches the goal of automating creation of Amazon infrastructure.
Why this answer
AWS CloudFormation is the infrastructure-as-code (IaC) service that allows you to define AWS resources such as EC2 instances, security groups, and IAM roles in declarative JSON or YAML templates. It automates provisioning and management of the entire stack, ensuring consistent and repeatable deployments. This directly matches the requirement to define infrastructure as code.
Exam trap
SOA-C02 often tests the distinction between IaC services and deployment/configuration services, so candidates must recognize that CloudFormation is the declarative IaC tool, while CodeDeploy, Elastic Beanstalk, and OpsWorks serve different purposes.
How to eliminate wrong answers
Option A is wrong because AWS Elastic Beanstalk is a PaaS service that abstracts infrastructure for deploying applications, but it does not provide declarative IaC templates for defining arbitrary resources like security groups and IAM roles. Option B is wrong because AWS CodeDeploy is a deployment service for automating application deployments to EC2, Lambda, or on-premises servers, not for defining infrastructure. Option D is wrong because AWS OpsWorks is a configuration management service using Chef and Puppet, which manages server configuration but is not the primary IaC service for defining AWS resources declaratively.