AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy

A financial services company is deploying a new critical application to AWS. They use AWS CloudFormation to manage their infrastructure. The security team has mandated that certain core resources, such as the production database and critical IAM roles, must not be accidentally deleted or updated without explicit, controlled processes. How can the DevOps team best implement this requirement using CloudFormation?

  1. AManually review all CloudFormation change sets before execution for critical stacks.
  2. BImplement AWS Config rules to monitor changes to these resources and trigger alerts.
  3. CApply a CloudFormation stack policy to the stacks containing the critical resources.
  4. DUse IAM policies to restrict CloudFormation service role permissions for these resources.
Show answer & explanation

Correct answer: C. Apply a CloudFormation stack policy to the stacks containing the critical resources.

CloudFormation stack policies are designed precisely for preventing unintended updates or deletions of specific stack resources. They act as a protection layer at the stack level, specifying which resources can be updated or deleted and under what conditions.

Why the other options are wrong

  • A. Manual review is a procedural control, not an automated technical control that prevents accidental changes at the CloudFormation engine level.
  • B. AWS Config rules monitor for compliance and changes but do not prevent actions on resources within a CloudFormation stack.
  • D. While IAM policies control what the CloudFormation service role can do, a stack policy specifically targets modifications to the stack's resources themselves, providing a more granular and intended control for this scenario.

CloudFormation Stack Policies

A JSON-formatted document that defines which update actions can be performed on designated resources within a CloudFormation stack. They prevent unintentional updates or deletions of critical stack resources.

  • Applied at the stack level.
  • Prevent specific update/delete actions on resources.
  • Overrides IAM permissions for update actions.
  • Defined in JSON.

Memory trick: Stacks need a solid 'Policy' shield to prevent accidental 'Drift'.

More Configuration Management and Infrastructure as Code questions