Deploying a CloudFormation StackSet with a custom-named IAM role to new Regions
A solutions architect is preparing to deploy a new security tool into several previously unused AWS Regions. The solutions architect will deploy the tool by using an AWS CloudFormation stack set. The stack set's template contains an IAM role that has a custom name. Upon creation of the stack set, no stack instances are created successfully. What should the solutions architect do to deploy the stacks successfully?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A StackSet to unused Regions fails until the Regions are enabled in the target accounts AND CAPABILITY_NAMED_IAM is specified, because custom IAM resource names require explicit acknowledgement before CloudFormation creates them.
A StackSet deployment to previously unused Regions fails to create stack instances when its template contains a custom-named IAM role. Two independent blockers must be cleared: the target Regions must be enabled in each account, and the CAPABILITY_NAMED_IAM capability must be acknowledged so CloudFormation can create the named IAM role.
Assuming the permission model (SELF_MANAGED vs SERVICE_MANAGED) or a custom administration role ARN is the blocker. The failure is on Region enablement and the named-IAM capability, not on the default permission model.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A removes both blockers. Previously unused Regions must be enabled in each target account before resources can be created there, and a template containing a custom-named IAM role (AWS::IAM::Role with a Name property) requires the CAPABILITY_NAMED_IAM capability to be acknowledged at StackSet creation. With both addressed, stack instances deploy successfully.Why the Other Options Are Wrong
Option B requests a quota increase and specifies only CAPABILITY_IAM, which does not satisfy the named-IAM requirement and does not enable the new Regions. Option C adds SELF_MANAGED but still omits Region enablement and is not the minimal correct fix. Option D specifies an administration role ARN with CAPABILITY_IAM, again missing both the Region enablement and the named-IAM capability.Community Comment Notes
kejam notes that stacks with IAM resources require CAPABILITY_NAMED_IAM or CAPABILITY_IAM. sat2008 points out the new Regions must first be enabled in the account and that the custom name needs CAPABILITY_NAMED_IAM. ele argues for C but overlooks the Region-enablement requirement.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →