Enforce EC2 Tags at Launch
A DevOps team manages a multi-account AWS environment using AWS Organizations. They need to enforce a mandatory tag (e.g., 'CostCenter') on all resources created across accounts. Which combination of services should be used to automatically remediate non-compliant resources?
⚠ Common exam trap
DOP-C02 often tests the misconception that SCPs can enforce tagging, but SCPs only control permissions, not resource configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.
AWS Config rules continuously evaluate resource configurations against desired tag policies. When a resource is non-compliant, Config can trigger automatic remediation using AWS Systems Manager Automation documents or Lambda functions to add the required tag or stop/delete the resource. This combination provides detection and automated enforcement across all accounts in AWS Organizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Service Control Policies (SCPs) to deny creation of resources without the tag.
Why it's wrong here
Service Control Policies (SCPs) are a preventive guardrail that can deny IAM principals the ability to create resources without the required tag, but they cannot remediate resources that already exist or were created before the policy was in place. SCPs only apply to future API calls and do not contain logic to tag, stop, or delete existing non-compliant resources. As a result, they address the creation path but leave the current non-compliant inventory untouched.
- ✗
AWS CloudTrail to detect non-compliant resource creation and send notifications.
Why it's wrong here
CloudTrail records API activity as an audit log and can be used for detection, but it is not a compliance engine and does not evaluate the eventual state of resources or trigger remediation directly. You could build a custom solution that sends CloudTrail events to Amazon EventBridge and invokes a Lambda function to tag or remove resources, but that requires custom code and still does not handle resources that existed before CloudTrail was enabled or configurations that drift without an API call. Therefore, CloudTrail remains a detective control, not a corrective one.
- ✓
AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.
Why this is correct
AWS Config rules continuously evaluate resource configurations, including tags, against your desired policy and can trigger automatic remediation when a resource is non-compliant. Remediation actions are implemented through AWS Systems Manager Automation runbooks, such as AWS-TagEC2Instance to add the required tag or AWS-StopEC2Instance to stop the resource, or through a custom Lambda function. This provides a fully automated, auditable corrective control that detects and fixes tag non-compliance at scale without manual intervention.
- ✗
AWS Resource Groups & Tag Editor to manually add tags to non-compliant resources.
Why it's wrong here
The Resource Groups & Tag Editor is an interactive tool that lets you search for resources across accounts and regions and manually add, modify, or remove tags in bulk. It is not event-driven or scheduled, so it cannot continuously monitor for new non-compliant resources or automatically apply tags when a resource is created. While useful for one-time cleanup, it does not provide automation, remediation logic, or ongoing compliance enforcement.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.