Empty an S3 bucket with a Lambda-backed CloudFormation custom resource before stack deletion

Answer Correct answer: A — Add a Lambda-backed custom resource with DependsOn pointing to the S3 bucket so the objects are removed before the stack is deleted.

Accompany runs an application on Amazon EC2 and AWS Lambda. The application stores temporary data in Amazon S3. The S3 objects are deleted after 24 hours. The company deploys new versions of the application by launching AWS CloudFormation stacks. The stacks create the required resources. After validating a new version, the company deletes the old stack. The deletion of an old development stack recently failed. A solutions architect needs to resolve this issue without major architecture changes. Which solution will meet these requirements?

  1. Create a Lambda function to delete objects from an S3 bucket. Add the Lambda function as a custom resource in the CloudFormation stack with a DependsOn attribute that points to the S3 bucket resource. Correct Answer
  2. Modify the CloudFormation stack to attach a DeletionPolicy attribute with a value of Delete to the S3 bucket.
  3. Update the CloudFormation stack to add a DeletionPolicy attribute with a value of Snapshot for the S3 bucket resource
  4. Update the CloudFormation template to create an Amazon Elastic File System (Amazon EFS) file system to store temporary files instead of Amazon S3. Configure the Lambda functions to run in the same VPC as the EFS file system.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CloudFormation refuses to delete a bucket that still contains objects, and a Lambda-backed custom resource runs during stack teardown, so it can empty the bucket before CloudFormation attempts to delete it.

Application versions are deployed by creating a CloudFormation stack and removing the old stack after validation. A stack deletion recently failed because the S3 bucket still held temporary objects, and no major architecture change is allowed.

Setting a DeletionPolicy on the bucket. CloudFormation only supports the Retain and Snapshot deletion policy values for S3 buckets, so a value of Delete is not valid for that resource type, and Retain or Snapshot would leave the bucket behind rather than solving the failure.

Community Discussion (14 comments)

gfhbox0083 👍 6 Selected: A
A, for sure. DeletionPolicy: Delete: The DeletionPolicy attribute in CloudFormation is used to specify what should happen to a resource when the stack is deleted. The value Delete indicates that CloudFormation should delete the resource (in this case, the S3 bucket) when the stack is deleted. Non-Empty Buckets: The problem with this approach is that CloudFormation cannot delete an S3 bucket if it contains any objects. The DeletionPolicy: Delete does not change this behavior; it only specifies that the bucket should be deleted, which will still fail if the bucket is not empty.
SIJUTHOMASP 👍 1 Selected: A
Repeated question.
nimbus_00 👍 2 Selected: A
common scenario. https://repost.aws/questions/QUvAaCd6J7To-Fs-eReXMgNg/to-add-an-aws-custom-resource-to-cloudformation-template-and-provide-an-aws-lambda-function
AzureDP900 👍 1
A is right By creating a Lambda function that deletes objects from the S3 bucket, you can ensure that the old CloudFormation stack is deleted even if the deletion process fails. Attaching this Lambda function as a custom resource in the CloudFormation stack allows CloudFormation to wait for the delete operation to complete before proceeding with the deletion of the old stack. The DependsOn attribute ensures that the Lambda function runs after the S3 bucket has been deleted, preventing any potential issues with deleting objects that may not be removed yet. Attaching this custom resource solves the issue without requiring major architecture changes.
JoeTromundo 👍 2 Selected: A
By using a Lambda function as a custom resource, you can ensure that the Lambda function deletes the objects in the S3 bucket before CloudFormation attempts to delete the bucket itself. Adding the DependsOn attribute ensures that the S3 bucket resource will not be deleted until the Lambda function has completed its task of clearing out all objects from the bucket, thus avoiding any errors caused by attempting to delete a non-empty S3 bucket. Options B and C: These options will not work because the DeletionPolicy attribute does NOT trigger the deletion of the OBJECTS INSIDE THE BUCKET. It ONLY determines what happens to the BUCKET RESOURCE ITSELF, not its contents. The stack deletion will still fail if objects remain in the bucket. Option D introduces significant architectural changes, which are unnecessary for solving the stack deletion issue.
gfhbox0083 👍 2
A, for sure. DeletionPolicy: Delete: The DeletionPolicy attribute in CloudFormation is used to specify what should happen to a resource when the stack is deleted. The value Delete indicates that CloudFormation should delete the resource (in this case, the S3 bucket) when the stack is deleted. Non-Empty Buckets: The problem with this approach is that CloudFormation cannot delete an S3 bucket if it contains any objects. The DeletionPolicy: Delete does not change this behavior; it only specifies that the bucket should be deleted, which will still fail if the bucket is not empty.
ahrentom 👍 3 Selected: A
you can´t delete a S3 bucket with objects in it. So A is correct
Russs99 👍 1 Selected: B
By setting the Deletion Policy attribute to Delete in the stack, you ensure that the S3 bucket and its contents are deleted when the CloudFormation stack is deleted. This best option for the scenario and and aligns with the desired behavior of removing old resources when the stack is deleted.
Alagong 👍 3 Selected: A
IT SHOULD BE A
AhmedSalem 👍 4 Selected: A
I will go for A. Using Lambda function as a custom resource ensures that the S3 bucket is emptied before the stack is deleted. DependsOn Attribute ensures the Lambda function runs and completes before attempting to delete the S3 bucket, thus preventing deletion failure.
grandcanyon 👍 1 Selected: B
When you specify a DeletionPolicy attribute with a value of Delete for an S3 bucket in a CloudFormation template, CloudFormation will delete the bucket and all its contents during stack deletion. This approach addresses the issue of the stack deletion failing due to the bucket not being empty.
Helpnosense 👍 1 Selected: C
Votes C. After s3 snapshot, cloud formation will proceed s3 bucket deletion. A is right but compare to c it doesn't match the requirement in the question. "resolve this issue without major architecture changes." Also the data become useless only after 24 hours. A delete everything regardless. C is better.
toma 👍 4
it should be A
mifune 👍 1 Selected: A
"DependsOn" attribute ensures that the Lambda function will always be invoked before the S3 bucket is deleted in a CloudFormation. Answer A.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A custom resource makes CloudFormation invoke a Lambda function as part of the stack lifecycle, and the DependsOn attribute guarantees the function runs only after the S3 bucket resource exists, so the bucket is guaranteed to be present when the function needs to empty it. During stack deletion the function deletes the objects, which removes the condition that caused the delete to fail, and CloudFormation can then remove the bucket. This is a small addition to the existing template and involves no architectural change.

Why the Other Options Are Wrong

B and C: CloudFormation supports only Retain and Snapshot as DeletionPolicy values for S3 buckets, so a value of Delete is not a valid setting, and both Retain and Snapshot leave the bucket in place rather than clearing the objects, so the original deletion failure is not resolved. D: Replacing S3 with an EFS file system is a major architectural change to the application's storage and Lambda networking, which the requirement explicitly rules out.

Community Comment Notes

The community voted 88 to 1 for A, and one commenter flagged this as a repeated question. The most-liked explanation confirmed that the custom resource empties the bucket before CloudFormation deletes it and that DependsOn ensures the ordering, while a re:Post link on custom resources in templates was cited as supporting evidence.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide