certslothcertsloth
SCS-C03/Topic 10

AWS / Specialty

CloudFormation and Systems Manager Operations

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Inspect the intended change, the actual state and the identity performing it.

Must remember

  • A CloudFormation stack tracks declared resources; dependencies control ordering. Change sets preview updates, drift detection compares supported properties with actual state, and StackSets apply stacks across selected accounts/Regions. These are different operations.
  • Know update-in-place versus replacement, rollback states and why a retained resource can survive stack deletion. DeletionPolicy controls supported deletion/retention behaviour; update-replacement retention is a separate concern. Imported resources and existing physical names need careful ownership checks.
  • Template parameters vary inputs; mappings select fixed values; conditions select resources/properties; outputs expose results. Resolve circular dependencies by reconsidering resource references and ordering. A creation signal or wait condition is not automatically satisfied by an EC2 instance entering running state.
  • Use service roles with least privilege and understand iam:PassRole. A user may initiate an operation while a service role performs it. Read stack events from the earliest meaningful failure, not only the final rollback summary.
  • Systems Manager managed nodes need a working agent, identity permissions and connectivity to required endpoints. Session Manager avoids opening SSH/RDP ports for supported access. Run Command executes commands, State Manager maintains associations, Automation coordinates runbooks, Patch Manager applies patch policies.
  • Maintenance windows define when approved work may run; patch baselines define approved patches. Inventory and compliance show state; remediation requires a configured action. Restrict runbook parameters and use approvals, rate controls and failure thresholds where the impact demands them.
  • Schedule start/stop and cleanup by explicit ownership tags. Stopped compute can leave charged storage and addresses. Cost Explorer, budgets, tags and anomaly detection provide evidence and alerts, not immediate universal spending caps.

Choose under exam pressure

Requirement Choice and reason
Same declared baseline across many accounts StackSets with appropriate delegated permissions.
Find console edits to managed resources Drift detection for supported properties.
Run an approved multi-step repair Systems Manager Automation runbook.

Traps

  • Drift detection does not automatically repair drift.
  • A successful stack update does not prove application readiness.
  • A service role can perform actions the initiating user cannot perform directly; control who may pass it.

Active recall

1. Where should you look first after a rollback?

Stack events around the original failure and the affected resource's service evidence.

2. Why can a managed node appear offline?

Agent, IAM, DNS, endpoint/network or clock/connectivity issues can prevent communication.

3. What differs between a patch baseline and a maintenance window?

Which patches are approved versus when operations may run.

4. Will deleting a stack necessarily delete every resource it once managed?

No. Retention policies, imports and failed deletions must be checked.

5. Why limit automation concurrency?

To contain blast radius and avoid exhausting dependencies while remediating many nodes.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.