Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A company uses AWS CloudFormation to deploy infrastructure. They want to enforce mandatory tags on all resources created by CloudFormation. Which TWO approaches can achieve this? (Choose TWO.)

⚠ Common exam trap

Many exam-takers confuse reactive detection (AWS Config) with proactive prevention (SCPs or stack tags), or mistakenly believe IAM policies can parse template content to enforce tagging rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use CloudFormation stack tags that propagate to all resources in the stack.

CloudFormation stack tags propagate to all resources that support tagging within the stack. When you specify tags at the stack level, CloudFormation automatically applies them to each resource it creates, ensuring mandatory tags are enforced without additional configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use CloudFormation stack tags that propagate to all resources in the stack.

    Why this is correct

    CloudFormation stack tags are specified on the stack and automatically propagated to every resource in the stack that supports tagging. Because CloudFormation applies these tags to resources during the CREATE or UPDATE operation, resources are born with the required tags, eliminating the need for a post-creation remediation step. This provides a native, preventive control that works without requiring any custom Lambda functions or additional configuration.

  • ✗

    Create an AWS Config rule to automatically tag resources after creation.

    Why it's wrong here

    An AWS Config rule is a detective control: it evaluates resource compliance after the resource has already been created. Even when you attach an auto-remediation action, remediation runs asynchronously, leaving a time window during which untagged resources exist and are usable. Config also does not support all resource types in its managed rules, and remediation relies on SSM automation, which may require additional IAM roles and can fail.

  • ✓

    Use an AWS Organizations service control policy (SCP) to deny creation of resources that are not tagged.

    Why this is correct

    An SCP can deny any resource creation action if the request does not include the required tags, using condition keys such as aws:RequestTag or service-specific keys like ec2:ResourceTag. Because SCPs apply to all principals in member accounts, including the CloudFormation service role, they can enforce tagging at creation across the entire organization. This is a preventive control that stops the operation before the resource is created, but it only works for services that support tag condition keys.

  • ✗

    Add an IAM policy that denies cloudformation:CreateStack unless the template includes the required tags.

    Why it's wrong here

    IAM policies inspect the API request, not the contents of a CloudFormation template. The cloudformation:CreateStack action includes a 'tags' parameter for stack-level tags, but IAM cannot see tags that are defined inside the template's resource declarations. Even if you deny CreateStack unless certain tags are passed, CloudFormation will still create resources whose template-defined tags may be absent, because IAM cannot evaluate template logic. Thus, this approach cannot enforce resource-level tagging.

  • ✗

    Enable AWS CloudTrail to log all API calls and monitor for untagged resources.

    Why it's wrong here

    CloudTrail is an auditing service that logs API activity; it does not intercept or block resource creation. While you can create CloudWatch Events rules to detect UntagResource or CreateResource calls that lack tags, this is purely a detective control, and any response requires separate automation. Untagged resources are already created and running by the time you see the event, making it impossible to prevent the violation. This is useful for operational visibility but not for compliance enforcement.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.