DOP-C02 Security and Compliance Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to restrict the use of specific instance types across all accounts to reduce costs and enforce compliance. Which approach should be used?
⚠ Common exam trap
DOP-C02 often tests the preventive-vs-detective distinction — candidates pick AWS Config or CloudFormation because they 'enforce' compliance, but only SCPs provide centralized, preventive, org-wide restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a service control policy (SCP) to the root organizational unit to deny the instance types
Service Control Policies (SCPs) in AWS Organizations set permission guardrails at the OU or account level and apply to all IAM principals within, including the root user. Attaching an SCP to the root OU that denies specific EC2 instance types enforces the restriction across every account in the organization in one place. This is the centralized, preventive control the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to detect non-compliant instance types
Why it's wrong here
AWS Config rules evaluate and flag existing resources after the fact; they detect non-compliant instance types but do not prevent their launch. Detection is tempting because Config gives organisation-wide compliance visibility, and it would be correct for auditing and reporting rather than blocking the action itself.
- ✓
Apply a service control policy (SCP) to the root organizational unit to deny the instance types
Why this is correct
Service control policies set the maximum available permissions for every principal in attached accounts, so a deny at the root organisational unit blocks those instance types organisation-wide. This centrally satisfies the cross-account restriction requirement without editing each account individually.
- ✗
Create IAM policies in each account to deny the use of the instance types
Why it's wrong here
IAM policies govern API permissions for identities, not which EC2 instance types an account may launch, so they cannot block instance selection. They are tempting because IAM is the usual access-control tool, and it would be correct for restricting who may call RunInstances, not which types they choose.
- ✗
Use AWS CloudFormation templates to enforce instance type selection
Why it's wrong here
CloudFormation templates only constrain resources created through those stacks; users launching instances by console, CLI or other tooling bypass them entirely. Templates are tempting because they enforce configuration at provisioning time, and would be correct where all workloads are deployed exclusively through managed CloudFormation stacks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.