Empty the non-empty S3 bucket from the custom resource's Lambda on Delete using RequestType Delete

Answer Correct answer: B — make the custom resource's Lambda function recursively empty the bucket when RequestType is Delete.

A company has developed a static website hosted on an Amazon S3 bucket. The website is deployed using AWS CloudFormation. The CloudFormation template defines an S3 bucket and a custom resource that copies content into the bucket from a source location. The company has decided that it needs to move the website to a new location, so the existing CloudFormation stack must be deleted and re-created. However, CloudFormation reports that the stack could not be deleted cleanly. What is the MOST likely cause and how can the DevOps engineer mitigate this problem for this and future versions of the website?

  1. Deletion has failed because the S3 bucket has an active website configuration. Modify the CloudFormation template to remove the WebsiteConfiguration property from the S3 bucket resource.
  2. Deletion has failed because the S3 bucket is not empty. Modify the custom resource's AWS Lambda function code to recursively empty the bucket when RequestType is Delete. Correct Answer
  3. Deletion has failed because the custom resource does not define a deletion policy. Add a DeletionPolicy property to the custom resource definition with a value of RemoveOnDeletion.
  4. Deletion has failed because the S3 bucket is not empty. Modify the S3 bucket resource in the CloudFormation template to add a DeletionPolicy property with a value of Empty.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The bucket fails deletion because it still contains objects, which is the documented behavior for CloudFormation's S3 bucket resource (B). The cleanup has to happen before bucket deletion, and the custom resource that populates the bucket is the natural owner of that responsibility, so its Lambda function implements the empty-on-Delete behavior. Option A addresses a static website configuration, which does not block deletion. Option C's DeletionPolicy applies to the custom resource itself rather than the bucket's contents. Option D's DeletionPolicy attribute is not a valid value for the S3 bucket resource, and a bucket DeletionPolicy would not empty it in any case.

CloudFormation cannot delete a non-empty S3 bucket, and the bucket is populated because a custom resource copies website content into it from a source location. The fix that also holds for future versions is to make the custom resource's Lambda function handle the Delete request type by recursively emptying the bucket, so that by the time CloudFormation attempts to delete the bucket resource it is empty and deletion succeeds. This keeps the cleanup logic inside the custom resource that owns the content.

Removing the WebsiteConfiguration property from the S3 bucket resource (A) — a static website configuration does not prevent CloudFormation from deleting a bucket, so this change has no bearing on the failure. Adding a DeletionPolicy of RemoveOnDeletion to the custom resource (C) — that attribute controls what happens to the custom resource itself on stack deletion, not whether the S3 bucket is empty. Setting a DeletionPolicy on the S3 bucket resource (D) — Empty is not a valid DeletionPolicy value for a bucket, and DeletionPolicy never empties bucket contents; only an explicit cleanup action does.

Community Discussion (6 comments)

youonebe 👍 2 Selected: B
You can only delete empty buckets. Deletion fails for buckets that have contents. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-s3-bucket.html
GripZA 👍 3 Selected: B
By default cloudformation can't delete an S3 bucket that's not empty. If the bucket still contains objects when the stack deletion is attempted, the stack deletion will fail. Although the Q doesn't specify that the custom resource uses Lambda. I think it's safe to assume here that since a custom resource is responsible for copying content into the bucket, it can also be used to handle the cleanup process.
tgv 👍 2
---> B
trungtd 👍 3 Selected: B
of course B
inturist 👍 3 Selected: B
Agree B
siheom 👍 3 Selected: B
Definitely B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CloudFormation will not delete an S3 bucket that still contains objects, and AWS documentation for the S3 bucket resource states this explicitly. In this template the bucket holds the website content because a custom resource copies it in from a source location, so the content must be removed before the stack can be deleted. The durable fix is to give the custom resource's Lambda function a Delete branch, keyed on the RequestType being Delete, that recursively empties the bucket. Because the same custom resource is used by every future version of the website, the mitigation is built in once and applies to subsequent deployments rather than requiring a manual cleanup each time (B). B is the correct answer.

Why the Other Options Are Wrong

A states deletion failed because the bucket has an active website configuration and proposes removing the WebsiteConfiguration property. A static website configuration has no bearing on whether CloudFormation can delete a bucket; the blocker is the presence of objects, so this change would not resolve the failure. C states the custom resource does not define a deletion policy and proposes adding a DeletionPolicy of RemoveOnDeletion to the custom resource. DeletionPolicy governs what happens to the resource it is attached to when the stack is deleted, in this case the custom resource itself; it does not empty the S3 bucket, so the bucket would still block deletion. D states the bucket is not empty and proposes adding a DeletionPolicy with the value Empty to the S3 bucket resource. Empty is not a valid DeletionPolicy value for an S3 bucket, and more fundamentally a DeletionPolicy never removes objects from a bucket, so even a valid value would not empty it. B is correct.

Community Comment Notes

Community voted B unanimously. youonebe cited the AWS documentation for the S3 bucket resource and noted that you can only delete empty buckets, so deletion fails when the bucket still contains objects. GripZA explained that CloudFormation cannot delete a non-empty S3 bucket by default, so if objects remain when stack deletion is attempted the deletion fails. trungtd, tgv, and inturist confirmed B without further qualification, and no alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide