AWS Certified SysOps Administrator – AssociateDeployment, Provisioning, and AutomationEasy
A development team uses AWS CloudFormation to manage their infrastructure. They frequently create and delete development environments, but sometimes forget to delete all associated resources, leading to orphaned resources and unexpected costs. They want to ensure that when a CloudFormation stack is deleted, all resources provisioned by that stack, including those with custom deletion policies, are always removed. Which CloudFormation feature should they leverage?
- ADeletionPolicy: Delete
- BDeletionPolicy: Snapshot
- CStack Policy
- DDeletionPolicy: Retain
Show answer & explanationAnswer & explanation
Correct answer: A. DeletionPolicy: Delete
By default, CloudFormation attempts to delete all resources when a stack is deleted. Setting 'DeletionPolicy: Delete' explicitly ensures that a resource is removed, even if it might otherwise have a default retention behavior (though this is rare for most resources, it's the explicit instruction for deletion). The question implies issues *despite* default behavior, and 'Delete' is the explicit instruction for removal.
Why the other options are wrong
- B. DeletionPolicy: Snapshot creates a snapshot of a resource before deleting it, still resulting in a resource (the snapshot) being retained.
- C. Stack Policies protect a stack from unintended updates or deletions, but do not control the deletion behavior of individual resources within the stack.
- D. DeletionPolicy: Retain prevents a resource from being deleted when its stack is deleted, leading to orphaned resources.
CloudFormation DeletionPolicy
A resource attribute in AWS CloudFormation templates that controls what happens to a resource when its containing stack is deleted or the resource is removed from the template.
- Can be set to Retain, Snapshot, or Delete.
- Retain prevents resource deletion.
- Snapshot creates a backup before deletion.
Memory trick: DeletionPolicy dictates destiny.