Question 913 of 1,511
Enforce EC2 Tags at Launch
A DevOps team wants to enforce that all EC2 instances launched in an AWS account have a specific tag 'Environment' with value 'Production' or 'Development'. The team uses AWS CloudFormation to provision resources. Which approach should the team use to enforce tagging compliance at launch?
Quick Answer
The correct answer is to use an AWS Config rule with an auto-remediation action that applies the required tag to non-compliant resources. This approach works because AWS Config continuously evaluates EC2 instances against a managed or custom rule that checks for the 'Environment' tag with allowed values of 'Production' or 'Development', and when non-compliance is detected—even at launch—the auto-remediation action triggers an AWS Systems Manager Automation document to automatically apply the missing tag. On the DOP-C02 exam, this scenario tests your understanding of how to enforce EC2 tags at launch using AWS Config auto-remediation, a key concept for maintaining compliance without blocking resource creation. A common trap is choosing a CloudFormation stack policy or a service control policy, but those either lack real-time enforcement or apply at the account level, not per resource. Memory tip: think "Config catches, Automation patches"—the rule detects the gap, and the automation fills it in, ensuring tagging compliance is enforced immediately after launch.
⚠ Common exam trap
A common mix-up: candidates confuse 'enforcement at launch' with 'prevention at launch' and incorrectly choose an IAM policy (Option B) or a Service Catalog constraint (Option C), not realizing that AWS Config with auto-remediation provides a more flexible and comprehensive enforcement mechanism that works across all launch methods and can correct non-compliance after the fact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an AWS Config rule with an auto-remediation action that applies the required tag to non-compliant resources.
AWS Config rules can evaluate EC2 instances for the presence of the 'Environment' tag with allowed values and, when combined with an auto-remediation action (e.g., using AWS Systems Manager Automation), can automatically apply the missing tag to non-compliant resources. This enforces tagging compliance at launch and throughout the resource lifecycle, even if the instance was launched without the tag. The auto-remediation action can be triggered as soon as the Config rule detects non-compliance, ensuring the tag is applied shortly after launch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a CloudFormation stack policy that denies stack updates if the tag is missing.
Why it's wrong here
Stack policies protect resources during updates, not enforce tags at launch.
- ✗
Add an IAM policy that denies ec2:RunInstances unless the request includes the required tag.
Why it's wrong here
IAM policies can require tags only if the ec2:RunInstances action checks for tags at launch, which is not possible without a service control policy (SCP) and proper condition keys.
- ✗
Create an AWS Service Catalog portfolio with a tag option constraint that requires the tag.
Why it's wrong here
Service Catalog only enforces tags for products launched through its portfolio, not for standalone CloudFormation stacks.
- ✓
Use an AWS Config rule with an auto-remediation action that applies the required tag to non-compliant resources.
Why this is correct
AWS Config can evaluate resources against rules and trigger auto-remediation to apply missing tags.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A DevOps engineer wants to ensure that all EC2 instances launched in an AWS account automatically have a specific set of tags applied for cost allocation. Which AWS service should they use to enforce this?
easy- A.AWS Service Catalog
- ✓ B.AWS Config
- C.Amazon EC2 Auto Scaling
- D.AWS CloudFormation
Why B: AWS Config is correct because it can enforce tagging rules through managed rules like `required-tags` or custom AWS Config rules using AWS Lambda. When an EC2 instance is launched without the required tags, AWS Config can evaluate the resource against the rule and trigger remediation actions (e.g., via AWS Systems Manager Automation) to automatically apply the tags or flag non-compliance. This ensures consistent cost allocation tagging across all instances without manual intervention.
Variation 2. A DevOps team manages a multi-account AWS environment using AWS Organizations. They need to enforce a mandatory tag (e.g., 'CostCenter') on all resources created across accounts. Which combination of services should be used to automatically remediate non-compliant resources?
hard- A.AWS Service Control Policies (SCPs) to deny creation of resources without the tag.
- B.AWS CloudTrail to detect non-compliant resource creation and send notifications.
- ✓ C.AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.
- D.AWS Resource Groups & Tag Editor to manually add tags to non-compliant resources.
Why C: AWS Config rules can evaluate resources for mandatory tags and trigger automatic remediation actions, such as AWS Systems Manager Automation or AWS Lambda functions, to add the missing tag. Option A is incorrect because SCPs only deny actions at the account level, but they do not remediate existing non-compliant resources or enforce tags on resources created outside the SCP scope. Option B is incorrect because CloudTrail only logs API calls and cannot automatically remediate non-compliant resources. Option D is incorrect because Tag Editor is a manual tool and does not provide automated enforcement or remediation.
Last reviewed: Jun 24, 2026
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.