Courseiva

SOA-C02 Practice Question: CloudFormation drift detection to identify…

Operators have been making direct changes to AWS resources (security group rules, IAM policy modifications) that were originally created by CloudFormation stacks. The team wants to identify which stacks and specific resources have drifted from their template definitions. What is the correct tool and operation sequence?

⚠ Common exam trap

Watch out — candidates often confuse drift detection with compliance checks (AWS Config) or remediation actions (update-stack), but the question specifically asks for identification of drifted stacks and resources, not remediation or compliance evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run drift detection on each CloudFormation stack; review the results in the Drift status panel to see which resources have MODIFIED or DELETED status

AWS CloudFormation drift detection is the correct tool because it directly compares the current state of resources in a stack (including security group rules and IAM policies) against the stack's template definitions. Running drift detection on each stack and reviewing the Drift status panel reveals which resources have been modified or deleted outside of CloudFormation, providing the exact identification the team needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run drift detection on each CloudFormation stack; review the results in the Drift status panel to see which resources have MODIFIED or DELETED status

    Why this is correct

    Drift detection calls AWS APIs to read the current configuration of each resource and compares it to the template. Resources with live configurations differing from the template are marked MODIFIED. Deleted resources outside the stack are marked DELETED. The results show the exact property-level differences, enabling targeted remediation.

  • ✗

    Enable AWS Config conformance packs that check CloudFormation stack compliance against desired template states

    Why it's wrong here

    Config conformance packs check resources against config rules (e.g., security group open ports, IAM policy conditions). They do not compare resource attributes against a CloudFormation template definition. Drift detection is purpose-built for the template-vs-live comparison.

  • ✗

    Re-deploy all stacks with the original templates using CloudFormation update-stack to overwrite any manual changes

    Why it's wrong here

    Running update-stack with an unchanged template may overwrite manual changes, but only for properties the template specifies. It is a remediation action, not a detection action. The team needs to know which resources drifted before deciding whether to remediate. Drift detection provides the discovery step.

  • ✗

    Use AWS Trusted Advisor to identify resources that have been modified outside of their originating CloudFormation stacks

    Why it's wrong here

    AWS Trusted Advisor is an advisory service that evaluates accounts against best practices in categories such as cost optimization, performance, security, and fault tolerance; it does not perform a resource-by-resource comparison against CloudFormation template definitions. Its checks (e.g., EBS snapshots, security group rules, service limits) are generic and not scoped to a specific stack or its declared resources. To find manual modifications, you need AWS CloudFormation drift detection, which uniquely inspects each stack's live resource configuration and reports per-property differences against the original template. Trusted Advisor simply lacks the template-aware logic required to identify which resources have been altered outside of stack management.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.