Empty an S3 bucket with a Lambda-backed CloudFormation custom resource before stack deletion
Accompany runs an application on Amazon EC2 and AWS Lambda. The application stores temporary data in Amazon S3. The S3 objects are deleted after 24 hours. The company deploys new versions of the application by launching AWS CloudFormation stacks. The stacks create the required resources. After validating a new version, the company deletes the old stack. The deletion of an old development stack recently failed. A solutions architect needs to resolve this issue without major architecture changes. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
CloudFormation refuses to delete a bucket that still contains objects, and a Lambda-backed custom resource runs during stack teardown, so it can empty the bucket before CloudFormation attempts to delete it.
Application versions are deployed by creating a CloudFormation stack and removing the old stack after validation. A stack deletion recently failed because the S3 bucket still held temporary objects, and no major architecture change is allowed.
Setting a DeletionPolicy on the bucket. CloudFormation only supports the Retain and Snapshot deletion policy values for S3 buckets, so a value of Delete is not valid for that resource type, and Retain or Snapshot would leave the bucket behind rather than solving the failure.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A custom resource makes CloudFormation invoke a Lambda function as part of the stack lifecycle, and the DependsOn attribute guarantees the function runs only after the S3 bucket resource exists, so the bucket is guaranteed to be present when the function needs to empty it. During stack deletion the function deletes the objects, which removes the condition that caused the delete to fail, and CloudFormation can then remove the bucket. This is a small addition to the existing template and involves no architectural change.Why the Other Options Are Wrong
B and C: CloudFormation supports only Retain and Snapshot as DeletionPolicy values for S3 buckets, so a value of Delete is not a valid setting, and both Retain and Snapshot leave the bucket in place rather than clearing the objects, so the original deletion failure is not resolved. D: Replacing S3 with an EFS file system is a major architectural change to the application's storage and Lambda networking, which the requirement explicitly rules out.Community Comment Notes
The community voted 88 to 1 for A, and one commenter flagged this as a repeated question. The most-liked explanation confirmed that the custom resource empties the bucket before CloudFormation deletes it and that DependsOn ensures the ordering, while a re:Post link on custom resources in templates was cited as supporting evidence.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →