AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A CloudOps engineer runs "cdk deploy" to launch a stack that creates an Amazon ECS task execution role. The deployment consistently fails with the message "User is not authorized to perform iam:PassRole" even though the engineer's IAM user has that permission. The project uses a dedicated CloudFormation execution role named cfn-exec-role that already has AdministratorAccess attached. What is the MOST appropriate way to remediate the failure so the deployment succeeds?

  • Add a Name tag to the ECS task execution role resource so CloudFormation can reference it during creation.

  • Attach the iam:PassRole permission to the engineer's IAM user instead of the execution role, then run the deployment again.

  • Enable CloudFormation termination protection on the stack and retry the deployment to bypass the error.

  • Add a policy to cfn-exec-role that explicitly allows iam:PassRole on the ARN of the new ECS task execution role and redeploy the stack.

AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot