Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is implementing AWS Config rules to enforce tagging standards on resources. The rule should trigger a remediation action via AWS Systems Manager Automation to apply the correct tags if a resource is non-compliant. What is the correct way to set up this remediation?

⚠ Common exam trap

The trap here is that candidates may over-engineer a solution with Lambda or CloudWatch Events, not realizing that AWS Config has a built-in, one-click remediation action that directly invokes SSM Automation documents, making it the simplest and most correct approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the AWS Config rule's remediation action to run an AWS Systems Manager Automation document.

AWS Config rules can directly associate a remediation action using an AWS Systems Manager Automation document. When a resource is evaluated as non-compliant, Config can automatically invoke the specified SSM Automation document to apply the correct tags, without requiring intermediate services. This is the native, supported mechanism for auto-remediation of non-compliant resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use the AWS Config rule's remediation action to run an AWS Systems Manager Automation document.

    Why this is correct

    AWS Config rules natively support an automated remediation feature that links a non-compliant rule evaluation to an AWS Systems Manager Automation document. This is the intended, first-party mechanism: the Automation document can run pre-built or custom steps (e.g., AWS-TagResource) to fix tag violations, and Config can automatically apply remediation to affected resources. Because it is built into the Config service itself, it avoids the need to wire separate event routing or manual workflows, making it the most direct and operationally efficient option.

  • ✗

    Configure the AWS Config rule to send events to AWS CodePipeline to trigger a pipeline that fixes the tags.

    Why it's wrong here

    AWS Config does not provide a built-in integration to emit rule compliance events directly into AWS CodePipeline; CodePipeline is designed for CI/CD orchestration of application builds and releases, not for AWS resource governance. To make this work, you would have to create an intermediate mechanism (such as a Lambda function or custom event bridge) to invoke the pipeline, and the pipeline itself would need a custom action to apply tags. This adds complexity and is not a native remediation path, so it is less appropriate than using Config's own remediation action.

  • ✗

    Configure a CloudWatch Events rule to detect non-compliant resources and invoke a Lambda function that applies tags.

    Why it's wrong here

    A CloudWatch Events (now Amazon EventBridge) rule can match Config non-compliance events and invoke a Lambda function to add tags, which does resolve the violation. However, this approach is a custom workaround: it requires you to provision and manage an event rule, a Lambda function, and its IAM role, and then handle retries, throttling, and failures yourself. AWS Config already offers a first-class remediation feature that runs an Automation document, so this option duplicates that functionality with unnecessary moving parts and is not the recommended native mechanism.

  • ✗

    Use an SNS topic to notify administrators when a resource is non-compliant.

    Why it's wrong here

    An SNS topic can notify administrators or on-call engineers when a resource is flagged non-compliant, which supports alerting and visibility. But notifications alone cannot change the resource state; they only create a manual follow-up task. Since the question specifically asks for enforcement (fixing the missing tags), a notification mechanism is insufficient and does not provide any automated remediation, making it inferior to Config's built-in remediation action.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.