AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A DevOps engineer maintains a CloudFormation stack that provisions an Amazon RDS DB instance plus hundreds of other resources. Management mandates that future stack updates must never delete or replace the existing database, while allowing normal updates to all other resources. The engineer wants a reusable, stack-level control that does not require changing the template for each release. Which approach meets these requirements?
Add the DeletionPolicy attribute set to Retain on the DB instance within the template.
Enable termination protection on the stack so the DB instance cannot be modified.
Attach a stack policy that explicitly denies Update:Replace and Delete actions on the DB instance's logical ID.
Run drift detection before every update and cancel the deployment if the DB instance is listed.
A stack policy is evaluated during CloudFormation operations. By attaching a policy that denies Update:Replace and Delete actions on the logical ID representing the DB instance, the database is protected from replacement or deletion, yet the same stack can continue to update other resources. Termination protection blocks the entire stack from being deleted but does not stop an update from replacing a resource. The DeletionPolicy attribute only takes effect during stack deletion, not during updates. Drift detection is read-only; it reports configuration differences but cannot prevent changes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are stack policies in AWS CloudFormation?
Open an interactive chat with Bash
How does the DeletionPolicy attribute work in CloudFormation templates?
Open an interactive chat with Bash
What is the purpose of termination protection on a CloudFormation stack?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .