Deploying a CloudFormation StackSet with a custom-named IAM role to new Regions

Answer Correct answer: A — Enable the new Regions in the target accounts and specify CAPABILITY_NAMED_IAM so CloudFormation can create the custom-named IAM role and deploy the stacks.

A solutions architect is preparing to deploy a new security tool into several previously unused AWS Regions. The solutions architect will deploy the tool by using an AWS CloudFormation stack set. The stack set's template contains an IAM role that has a custom name. Upon creation of the stack set, no stack instances are created successfully. What should the solutions architect do to deploy the stacks successfully?

  1. Enable the new Regions in all relevant accounts. Specify the CAPABILITY_NAMED_IAM capability during the creation of the stack set. Correct Answer
  2. Use the Service Quotas console to request a quota increase for the number of CloudFormation stacks in each new Region in all relevant accounts. Specify the CAPABILITY_IAM capability during the creation of the stack set.
  3. Specify the CAPABILITY_NAMED_IAM capability and the SELF_MANAGED permissions model during the creation of the stack set.
  4. Specify an administration role ARN and the CAPABILITY_IAM capability during the creation of the stack set.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A StackSet to unused Regions fails until the Regions are enabled in the target accounts AND CAPABILITY_NAMED_IAM is specified, because custom IAM resource names require explicit acknowledgement before CloudFormation creates them.

A StackSet deployment to previously unused Regions fails to create stack instances when its template contains a custom-named IAM role. Two independent blockers must be cleared: the target Regions must be enabled in each account, and the CAPABILITY_NAMED_IAM capability must be acknowledged so CloudFormation can create the named IAM role.

Assuming the permission model (SELF_MANAGED vs SERVICE_MANAGED) or a custom administration role ARN is the blocker. The failure is on Region enablement and the named-IAM capability, not on the default permission model.

Community Discussion (7 comments)

kejam 👍 6 Selected: A
Some stack templates might include resources that can affect permissions in your AWS account; for example, by creating new AWS Identity and Access Management (IAM) users. For those stacks, you must explicitly acknowledge this by specifying one of these capabilities. https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_CreateStack.html
sat2008 👍 5 Selected: A
Question says "several previously unused AWS Regions" so you have to enable them under the Account first ? And the CAPABILITY_NAMED_IAM for the custom name
AzureDP900 👍 2
The correct answer is A. When deploying a CloudFormation stack set to multiple Regions, you need to ensure that the IAM role has sufficient permissions to create stacks in those Regions. The issue here is likely due to a limitation on the number of CloudFormation stacks that can be created in a Region. To resolve this issue, you should: Enable the new Regions in all relevant accounts. Specify the CAPABILITY_NAMED_IAM capability during the creation of the stack set. This allows AWS to create stacks without having to manage IAM roles for each stack instance.
career360guru 👍 1 Selected: A
A seems to be the right choice
ele 👍 1 Selected: C
C is the answer. The following resources require you to specify CAPABILITY_IAM or CAPABILITY_NAMED_IAM: AWS::IAM::Group, AWS::IAM::InstanceProfile, AWS::IAM::Policy, and AWS::IAM::Role. If the application contains IAM resources with custom names, you must specify CAPABILITY_NAMED_IAM. With self-managed permissions, you create the AWS Identity and Access Management (IAM) roles required by StackSets to deploy across accounts and AWS Regions. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-prereqs-self-managed.html https://docs.aws.amazon.com/serverlessrepo/latest/devguide/acknowledging-application-capabilities.html
HunkyBunky 👍 1 Selected: A
Proper answer is - A We want to create Cloudformation stack that contains IAM role with custom name - so we need to set CAPABILITY_NAMED_IAM
alexis123456 👍 3
Correct A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A removes both blockers. Previously unused Regions must be enabled in each target account before resources can be created there, and a template containing a custom-named IAM role (AWS::IAM::Role with a Name property) requires the CAPABILITY_NAMED_IAM capability to be acknowledged at StackSet creation. With both addressed, stack instances deploy successfully.

Why the Other Options Are Wrong

Option B requests a quota increase and specifies only CAPABILITY_IAM, which does not satisfy the named-IAM requirement and does not enable the new Regions. Option C adds SELF_MANAGED but still omits Region enablement and is not the minimal correct fix. Option D specifies an administration role ARN with CAPABILITY_IAM, again missing both the Region enablement and the named-IAM capability.

Community Comment Notes

kejam notes that stacks with IAM resources require CAPABILITY_NAMED_IAM or CAPABILITY_IAM. sat2008 points out the new Regions must first be enabled in the account and that the custom name needs CAPABILITY_NAMED_IAM. ele argues for C but overlooks the Region-enablement requirement.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide