Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

Exhibit

Refer to the exhibit.

{
  "AWSTemplateFormatVersion": "2010-09-09",
  "Resources": {
    "MyEC2Instance": {
      "Type": "AWS::EC2::Instance",
      "Properties": {
        "ImageId": "ami-0abcdef1234567890",
        "InstanceType": "t2.micro",
        "SecurityGroups": [ "default" ]
      }
    },
    "MyElasticIP": {
      "Type": "AWS::EC2::EIP",
      "Properties": {
        "InstanceId": { "Ref": "MyEC2Instance" }
      }
    }
  }
}

Refer to the exhibit. A SysOps administrator creates this CloudFormation template. The stack creation fails with the error: 'The security group 'default' does not exist'. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The instance is launched in a VPC, but the security group is specified by name instead of group ID.

The error occurs because the template launches the instance in a VPC, where security groups must be referenced by their GroupId, not by name. The template uses 'default' (a name), but CloudFormation interprets it as a GroupId, which does not exist, causing the failure. Option C correctly identifies this issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPC does not have a default security group.

    Why it's wrong here

    This is incorrect because every default VPC is automatically created with a default security group. AWS provisions a default security group named "default" for each VPC, and you cannot remove it from a standard VPC. Therefore, a missing default security group in the VPC is not the cause of the error; the group exists but is being referenced incorrectly.

  • ✗

    The instance is launched in EC2-Classic, which does not support security groups.

    Why it's wrong here

    This is incorrect because EC2-Classic actually supports security groups, though it identifies them by name rather than by group ID. However, EC2-Classic was deprecated and is unavailable to most modern AWS accounts; more importantly, the error occurs because the instance was launched in a VPC, where EC2-Classic name-based resolution does not apply. Thus, EC2-Classic's support for security groups is irrelevant and not the reason.

  • ✓

    The instance is launched in a VPC, but the security group is specified by name instead of group ID.

    Why this is correct

    This is correct because when you launch an instance in a VPC, AWS requires you to reference security groups by their group ID (e.g., sg-12345678), not by their name. In a VPC, the CLI parameter "--security-group-ids" expects the resource ID, and passing the name "default" (how it appears in the console) causes a "security group does not exist" error. The default VPC's default security group has a unique ID, and you must retrieve and use that ID to successfully launch the instance.

  • ✗

    The 'default' security group is not present in the account.

    Why it's wrong here

    This is incorrect because every VPC, including nondefault VPCs you create, includes a default security group that cannot be deleted. AWS documentation states that the default security group is permanent in each VPC and the default group ID is assigned when the VPC is created. Therefore, the default security group is always present in the account, so its absence cannot explain the failure; the issue is that the user passed its name instead of its group ID.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.