AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeEasy

A development team is deploying a new microservice to AWS using AWS CloudFormation. They need to ensure that the Amazon S3 bucket used by the microservice is created with specific encryption settings and access policies to comply with corporate security standards. The team wants to prevent any manual changes to these critical S3 bucket properties once the stack is deployed. Which CloudFormation feature should they use to achieve this?

  1. ACloudFormation Drift Detection
  2. BCloudFormation Change Sets
  3. CCloudFormation Stack Policies
  4. DAWS Config Rules
Show answer & explanation

Correct answer: C. CloudFormation Stack Policies

CloudFormation Stack Policies are designed to protect specified resources or resource properties within a stack from unintended updates, effectively preventing manual changes. Change Sets are for previewing changes, AWS Config Rules detect non-compliance, and Drift Detection identifies differences between the deployed stack and its template.

Why the other options are wrong

  • A. CloudFormation Drift Detection identifies when a stack's actual configuration differs from its template, but it doesn't prevent those differences from occurring.
  • B. CloudFormation Change Sets are used to preview how proposed changes to a stack will impact existing resources, not to prevent changes.
  • D. AWS Config Rules are used to evaluate whether your AWS resource configurations comply with desired settings, but they don't prevent changes directly.

CloudFormation Stack Policies

CloudFormation Stack Policies are JSON documents that define which resources or resource properties within a CloudFormation stack cannot be updated or deleted, protecting critical infrastructure.

  • Prevents unintended updates to specified resources/properties.
  • Applied to a stack to control update behavior.
  • Uses 'Allow' and 'Deny' statements for actions.
  • Does not apply to stack creation or deletion.

Memory trick: Stack Policies stand guard, preventing unauthorized changes to your infrastructure's core.

More Configuration Management and Infrastructure as Code questions