SOA-C02 Deployment, Provisioning, and Automation Practice Question
An organization wants to automate the creation of AWS resources using AWS CloudFormation. They need to ensure that certain resources, such as an Amazon S3 bucket, are not accidentally deleted when the stack is deleted. Which CloudFormation feature should they use?
⚠ Common exam trap
Watch out — candidates often confuse the DeletionPolicy attribute with a stack policy or incorrectly assume 'Protect' is a valid value, when in fact only 'Delete', 'Retain', and 'Snapshot' are permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeletionPolicy attribute with value 'Retain'
The DeletionPolicy attribute with value 'Retain' instructs AWS CloudFormation to preserve a resource when its stack is deleted. This is the correct feature to prevent accidental deletion of critical resources like an S3 bucket, as the bucket and its contents will remain in the account even after the stack is removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeletionPolicy attribute with value 'Retain'
Why this is correct
The DeletionPolicy attribute with value Retain is the correct CloudFormation resource-level setting to preserve an S3 bucket when its stack is deleted. It instructs CloudFormation to skip deleting the underlying resource, so the bucket and all objects remain in the AWS account as an orphaned resource. This is designed exactly for the use case of retaining stateful data such as S3 buckets or DynamoDB tables after infrastructure teardown.
- ✗
DeletionPolicy attribute with value 'Protect'
Why it's wrong here
The value 'Protect' is not one of the three valid DeletionPolicy values—Delete, Retain, and Snapshot—so CloudFormation would reject the template with a validation error before creating the stack. Even if a user mistakenly assumes 'Protect' implies retention, the AWS API enum constraint prevents it from being interpreted as a policy at all. The correct way to preserve the bucket is to set DeletionPolicy to Retain, never a nonexistent 'Protect' value.
- ✗
DeletionPolicy attribute with value 'Delete'
Why it's wrong here
DeletionPolicy with value Delete is actually the default behavior, meaning CloudFormation will attempt to remove the S3 bucket when the stack is deleted. If the bucket contains objects, the deletion often fails because a non-empty S3 bucket cannot be removed, which can cause the entire stack deletion to fail. In a scenario where the bucket must be retained regardless of contents, this option is wrong because it either destroys an empty bucket or blocks teardown rather than preserving the resource.
- ✗
Stack policy
Why it's wrong here
A stack policy is a JSON-based access-control document that CloudFormation applies during stack updates to prevent specific resources from being modified or deleted by update operations, such as Update:Modify and Update:Delete actions. It does not govern what happens during a stack deletion—at that point, CloudFormation evaluates the resource DeletionPolicy, not the stack policy. For this reason, a stack policy cannot keep the bucket around after stack deletion; it only guards against accidental changes while the stack is being updated.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.