AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company uses AWS CloudFormation to provision application stacks that include an IAM role with the AdministratorAccess managed policy attached. Application teams must be free to update the rest of their resources, but the CloudOps engineer must ensure that these critical roles can never be deleted or replaced during stack updates. What is the most operationally efficient way to meet this requirement?

  • Enable termination protection on every stack so CloudFormation blocks operations that would delete resources.

  • Deploy an AWS Config rule that detects changes to Administrator roles and triggers a Lambda function to roll back unauthorized modifications.

  • Attach a stack policy to each stack that denies Delete and Update:Replace actions for the logical IDs of the Administrator roles.

  • Add a DeletionPolicy of Retain to the IAM role resources in the templates.

AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot