AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A financial institution is deploying a new critical application to AWS. They use AWS CloudFormation for infrastructure provisioning. Due to strict compliance requirements, all infrastructure changes must be reviewed and approved before deployment, and any deviation from the approved template must be prevented. The security team also mandates that no resource can be accidentally deleted. Which AWS CloudFormation feature should be implemented to meet these requirements effectively?

  1. AApply CloudFormation Stack Policies to protect specific resources from unintended updates or deletions.
  2. BUtilize CloudFormation Drift Detection to identify resources that deviate from the template.
  3. CImplement AWS Config rules to detect and remediate non-compliant resource configurations.
  4. DUse CloudFormation Change Sets to preview changes and then manually execute them.
Show answer & explanation

Correct answer: A. Apply CloudFormation Stack Policies to protect specific resources from unintended updates or deletions.

CloudFormation Stack Policies are designed to prevent unintended updates or deletions of specific stack resources, which directly addresses the requirement of preventing accidental deletions and ensuring changes adhere to approved templates by restricting update actions. This provides a granular control mechanism for resource protection.

Why the other options are wrong

  • B. Drift Detection identifies deviations but does not prevent them from happening in the first place, nor does it prevent deletions.
  • C. AWS Config detects non-compliance after it occurs and can trigger remediation, but it doesn't prevent the initial change or deletion.
  • D. Change Sets allow previewing changes but do not prevent unauthorized changes or accidental deletions after execution.

CloudFormation Stack Policies

CloudFormation Stack Policies are JSON documents that define which update actions can be performed on specific stack resources. They are used to prevent unintentional updates or deletions of critical resources.

  • Applied to an entire stack, but rules can target specific resources.
  • Prevent unintended updates or deletions.
  • Default policy allows all updates unless overridden.
  • Useful for protecting critical production resources.

Memory trick: Stack Policies are like a digital shield for your CloudFormation castle.

More Configuration Management and Infrastructure as Code questions