Courseiva

Enforce EC2 Tags at Launch

A DevOps team manages a multi-account AWS environment using AWS Organizations. They need to enforce a mandatory tag (e.g., 'CostCenter') on all resources created across accounts. Which combination of services should be used to automatically remediate non-compliant resources?

⚠ Common exam trap

DOP-C02 often tests the misconception that SCPs can enforce tagging, but SCPs only control permissions, not resource configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.

AWS Config rules continuously evaluate resource configurations against desired tag policies. When a resource is non-compliant, Config can trigger automatic remediation using AWS Systems Manager Automation documents or Lambda functions to add the required tag or stop/delete the resource. This combination provides detection and automated enforcement across all accounts in AWS Organizations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Service Control Policies (SCPs) to deny creation of resources without the tag.

    Why it's wrong here

    Service Control Policies (SCPs) are a preventive guardrail that can deny IAM principals the ability to create resources without the required tag, but they cannot remediate resources that already exist or were created before the policy was in place. SCPs only apply to future API calls and do not contain logic to tag, stop, or delete existing non-compliant resources. As a result, they address the creation path but leave the current non-compliant inventory untouched.

  • ✗

    AWS CloudTrail to detect non-compliant resource creation and send notifications.

    Why it's wrong here

    CloudTrail records API activity as an audit log and can be used for detection, but it is not a compliance engine and does not evaluate the eventual state of resources or trigger remediation directly. You could build a custom solution that sends CloudTrail events to Amazon EventBridge and invokes a Lambda function to tag or remove resources, but that requires custom code and still does not handle resources that existed before CloudTrail was enabled or configurations that drift without an API call. Therefore, CloudTrail remains a detective control, not a corrective one.

  • ✓

    AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.

    Why this is correct

    AWS Config rules continuously evaluate resource configurations, including tags, against your desired policy and can trigger automatic remediation when a resource is non-compliant. Remediation actions are implemented through AWS Systems Manager Automation runbooks, such as AWS-TagEC2Instance to add the required tag or AWS-StopEC2Instance to stop the resource, or through a custom Lambda function. This provides a fully automated, auditable corrective control that detects and fixes tag non-compliance at scale without manual intervention.

  • ✗

    AWS Resource Groups & Tag Editor to manually add tags to non-compliant resources.

    Why it's wrong here

    The Resource Groups & Tag Editor is an interactive tool that lets you search for resources across accounts and regions and manually add, modify, or remove tags in bulk. It is not event-driven or scheduled, so it cannot continuously monitor for new non-compliant resources or automatically apply tags when a resource is created. While useful for one-time cleanup, it does not provide automation, remediation logic, or ongoing compliance enforcement.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.