Match the UPDATE_COMPLETE stack status in an EventBridge rule and invoke the tagging Lambda function

Answer Correct answer: C — match the UPDATE_COMPLETE status in an EventBridge rule and invoke the Lambda function that applies the tag.

A company has an AWS CloudFormation stack that is deployed in a single AWS account. The company has configured the stack to send event notifications to an Amazon Simple Notification Service (Amazon SNS) topic. A DevOps engineer must implement an automated solution that applies a tag to the specific CloudFormation stack instance only after a successful stack update occurs. The DevOps engineer has created an AWS Lambda function that applies and updates this tag for the specific stack instance. Which solution will meet these requirements?

  1. Run the AWS-UpdateCloudFormationStack AWS Systems ManagerAutomation runbook when Systems Manager detects an UPDATE_COMPLETE event for the instance status of the CloudFormation stack. Configure the runbook to invoke the Lambda function.
  2. Create a custom AWS Config rule that produces a compliance change event if the CloudFormation stack has an UPDATE_COMPLETE instance status. Configure AWS Config to directly invoke the Lambda function to automatically remediate the change event.
  3. Create an Amazon EventBridge rule that matches the UPDATE_COMPLETE event pattern for the instance status of the CloudFormation stack. Configure the rule to invoke the Lambda function. Correct Answer
  4. Adjust the configuration of the CloudFormation stack to send notifications for only an UPDATE_COMPLETE instance status event to the SNS topic. Subscribe the Lambda function to the SNS topic.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

EventBridge consumes CloudFormation events and can be filtered on the stack instance status, so a rule matching UPDATE_COMPLETE invokes the Lambda function precisely when the update succeeded and not before (C). Option A depends on Systems Manager detecting the status change, which is not how Systems Manager Automation works and adds an unnecessary runbook indirection. Option B's custom Config rule plus direct Lambda invocation does not exist as an integration. Option D repurposes the SNS topic that is already configured to receive all stack events, which would deliver every event rather than only the successful update.

Tagging must happen only after a successful update, and the signal for that is the CloudFormation stack instance reaching the UPDATE_COMPLETE status. An Amazon EventBridge rule with an event pattern matching that instance status invokes the existing Lambda function, which applies the tag to the specific stack. This reacts to the event directly and does not alter the stack's existing notification configuration.

Running the AWS-UpdateCloudFormationStack Systems Manager Automation runbook when Systems Manager detects UPDATE_COMPLETE (A) — this conflates two unrelated services: CloudFormation stack statuses are not Systems Manager detections, and an Automation document that updates a stack would be circular since the update has already completed. Relying on a custom Config rule to produce a compliance change event and invoking the Lambda function directly (B) — AWS Config does not invoke Lambda functions directly as a remediation target here, so this integration does not exist. Adjusting the stack's notification configuration to send only UPDATE_COMPLETE to the SNS topic and subscribing the Lambda function (D) — the stack is already configured to send all events to the topic, and restricting it would discard the other notifications the team relies on.

Community Discussion (4 comments)

GripZA 👍 3 Selected: C
EventBridge is designed to detect specific events in AWS services, and it can be configured to match events such as UPDATE_COMPLETE from CloudFormation. This allows you to automate the process of tagging the CloudFormation stack instancess whenever the UPDATE_COMPLETE event occurs. The EventBridge rule will trigger the Lambda function, which will then apply the necessary tag to the stack.
dkp 👍 3 Selected: C
options C and D are suitable for implementing the automated solution. However, using Option C with Amazon EventBridge is more direct and does not require additional SNS configuration
WhyIronMan 👍 3 Selected: C
C, EventBridge + Lambda Function https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-run-lambda-schedule.html
ogerber 👍 3 Selected: C
Its C, 100%

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The tagging must occur only after a successful update, and CloudFormation publishes an event when a stack instance reaches the UPDATE_COMPLETE status. An Amazon EventBridge rule whose event pattern matches that instance status can target the existing Lambda function directly, so the moment the update completes successfully the function runs and applies the tag to the specified stack instance (C). This is the most direct mechanism available: it consumes the service event, filters on the exact status, invokes the function, and leaves the stack's existing SNS notification configuration untouched.

Why the Other Options Are Wrong

A runs the AWS-UpdateCloudFormationStack Systems Manager Automation document when Systems Manager detects an UPDATE_COMPLETE event. CloudFormation stack instance statuses are reported through CloudFormation's own event channel, not detected by Systems Manager, and invoking a document that updates a stack after the update has already succeeded is both circular and unnecessary. WhyIronMan cited the EventBridge documentation as the correct mechanism. B creates a custom AWS Config rule that produces a compliance change event if the stack has an UPDATE_COMPLETE status and then configures AWS Config to invoke the Lambda function. AWS Config does not invoke Lambda functions directly in response to compliance change events, so the described integration does not function, and it also introduces a custom rule. D adjusts the stack's notification configuration so that only UPDATE_COMPLETE is sent to the SNS topic and subscribes the Lambda function to that topic. The stack is already configured to send event notifications to the topic, and narrowing it to a single status would suppress the other stack events the team depends on, making it a regression rather than a solution. C is the correct answer.

Community Comment Notes

Community voted C unanimously. GripZA explained that EventBridge is designed to detect specific AWS service events and can be configured to match CloudFormation UPDATE_COMPLETE, which automates the tagging. dkp noted that C is more direct than D because it requires no additional SNS configuration. WhyIronMan cited the EventBridge documentation for invoking Lambda, and ogerber confirmed C.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide