Deploy Lambda with a canary configuration and automatic rollback triggered by API Gateway 5XX alarms

Answer Correct answer: B — use LambdaCanary10Percent10Minutes with automatic rollback triggered by CloudWatch alarms detecting API Gateway 502 errors.

A DevOps team uses AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy to deploy an application. The application is a REST API that uses AWS Lambda functions and Amazon API Gateway. Recent deployments have introduced errors that have affected many customers. The DevOps team needs a solution that reverts to the most recent stable version of the application when an error is detected. The solution must affect the fewest customers possible. Which solution will meet these requirements with the MOST operational efficiency?

  1. Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold.
  2. Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure automatic rollbacks on the deployment group. Create an Amazon CloudWatch alarm that detects HTTP Bad Gateway errors on API Gateway. Configure the deployment group to roll back when the number of alarms meets the alarm threshold. Correct Answer
  3. Set the deployment configuration in CodeDeploy to LambdaAllAtOnce. Configure manual rollbacks on the deployment group. Create an Amazon Simple Notification Service (Amazon SNS) topic to send notifications every time a deployment fails. Configure the SNS topic to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.
  4. Set the deployment configuration in CodeDeploy to LambdaCanary10Percent10Minutes. Configure manual rollbacks on the deployment group. Create a metric filter on an Amazon CloudWatch log group for API Gateway to monitor HTTP Bad Gateway errors. Configure the metric filter to invoke a new Lambda function that stops the current deployment and starts the most recent successful deployment.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The two decisive requirements are minimizing affected customers and operational efficiency, which means automated rollback. A canary configuration shifts only 10 percent of traffic for 10 minutes before proceeding, so a bad release touches far fewer customers than an all-at-once deployment, and automatic rollback on a CloudWatch alarm reacts without a human (B). Using LambdaAllAtOnce (A, C) maximizes blast radius, and manual rollback or a metric filter invoking Lambda (C, D) adds custom code and human latency.

Because the API and Lambda tiers must be rolled back to the last stable version as soon as errors appear, and customer impact must be minimized, the deployment should shift a small percentage of traffic first and roll back automatically on failure. Using the LambdaCanary10Percent10Minutes deployment configuration with automatic rollback enabled, and configuring the deployment group to roll back when CloudWatch alarms detecting HTTP 502 errors on API Gateway breach their threshold, achieves both goals with no manual intervention.

Choosing LambdaAllAtOnce (A and C)—it replaces all traffic at the same time, so if the release is faulty the error affects every customer immediately, violating the requirement to affect as few customers as possible. Relying on manual rollback or a metric filter that triggers a new Lambda (C and D)—CloudWatch metric filters cannot invoke Lambda directly, and manual rollback is neither automated nor operationally efficient.

Community Discussion (6 comments)

thanhnv142 👍 8 Selected: B
B is correct: A and C: <CodeDeploy to LambdaAllAtOnce>: Replacing all at once would not allow roll back D: Metric filter cannot trigger lambda. Additionally, this options is a manual work
c3518fc 👍 3 Selected: B
Option B provides the most operationally efficient solution by combining canary deployments, automatic rollbacks, and CloudWatch alarms to detect and respond to issues quickly while minimizing customer impact.
dkp 👍 3 Selected: B
Answer B
ogerber 👍 3 Selected: B
Its B, 100%
Ramdi1 👍 1 Selected: C
option C - LambdaAllAtOnce: Rolling back everything at once minimizes the window for potential customer impact compared to canary deployments. Manual rollbacks: While automatic rollbacks may seem faster, they can be triggered by false positives, leading to unnecessary rollbacks and service disruptions. Manual rollbacks offer more control and allow the team to assess the situation before reverting. SNS notifications: Alerts about failing deployments are crucial for quick response. Lambda function for rollback: Automating the rollback process with a Lambda function triggered by SNS notification streamlines the operation and reduces manual intervention. Starts the most recent successful deployment: This ensures reverting to a known-good state without manual selection, saving time and avoiding errors.
Chelseajcole 👍 1
D. Rolling deployment with the option to stop once it detects any errors.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The canary deployment configuration LambdaCanary10Percent10Minutes routes only 10 percent of traffic to the new version for a 10-minute evaluation window before shifting the remainder, which limits the number of customers exposed if the release is defective. Enabling automatic rollback on the deployment group and configuring it to roll back when the CloudWatch alarm watching for HTTP 502 errors on API Gateway reaches its threshold means the previous stable version is restored programmatically the moment errors appear, with no operator action and no custom code.

Why the Other Options Are Wrong

A and C use LambdaAllAtOnce, which deploys the new version to all traffic simultaneously; a defective release then affects every customer at once, directly contradicting the requirement to affect as few customers as possible. C also depends on a new Lambda function invoked from SNS to stop and restart deployments, adding custom code and manual orchestration. D attempts to invoke Lambda from a CloudWatch metric filter, which metric filters cannot do, and combines it with manual rollback. B is the only option satisfying both the canary blast-radius limit and automated rollback.

Community Comment Notes

Community voted B (94). Commenters identified that LambdaAllAtOnce removes the rollback safety net and exposes all customers, and that metric filters cannot trigger Lambda, making D unworkable. One commenter argued for C on blast-radius grounds, but the canary plus automatic rollback combination in B best satisfies both stated requirements with the least manual effort.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide