DOP-C02 Security and Compliance Practice Question
Which THREE measures can be taken to ensure that EC2 instances are compliant with a security policy that requires all instances to be in a VPC with specific tags? (Select THREE.)
⚠ Common exam trap
Many candidates confuse detective controls (AWS Config) with preventive controls (SCPs) or assume that monitoring tools like CloudWatch can enforce compliance, when in fact they only alert on operational metrics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config rules to detect non-compliant instances.
AWS Config rules can evaluate EC2 instances against a desired configuration, such as being in a VPC with specific tags. By using a custom or managed rule (e.g., 'required-tags' or 'ec2-instance-in-vpc'), you can detect non-compliant instances and trigger remediation actions. This provides continuous monitoring and reporting of compliance status without blocking the launch itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Config rules to detect non-compliant instances.
Why this is correct
AWS Config rules continuously evaluate EC2 instances against compliance criteria such as mandatory tags or VPC membership. When an instance violates a rule, Config marks it non-compliant and can trigger remediation actions like Lambda functions, but it does not block the initial launch. This makes it a detective control that identifies drift after the fact rather than preventing non-compliant resources from being created.
- ✗
Use EC2 Auto Scaling to launch instances only in the correct VPC.
Why it's wrong here
EC2 Auto Scaling only controls the scaling of managed fleets and can specify a launch template or subnet, but it has no mechanism to verify or enforce tag requirements on instances. It also has no effect on instances launched manually or through other services, so resources can still be created outside the intended VPC. Thus, it cannot ensure compliance across all EC2 usage patterns.
- ✓
Apply an SCP that denies ec2:RunInstances unless the instance is in the correct VPC.
Why this is correct
A service control policy (SCP) in AWS Organizations can deny ec2:RunInstances unless the request includes a VPC subnet by using the ec2:Vpc condition key. This preventive control operates at the account level and applies to all principals, but it only works if the organization manages accounts through AWS Organizations. It effectively blocks non-compliant launches before they happen, unlike detective or corrective controls.
- ✓
Use a custom AWS Lambda function triggered by CloudTrail to tag instances.
Why this is correct
A custom Lambda function can be subscribed to CloudTrail events via Amazon EventBridge to react to RunInstances API calls, automatically applying required tags immediately after launch. This is a corrective control that tags instances without user involvement, but it has a time lag and may fail if the Lambda is misconfigured or throttled. It does not prevent untagged instances from existing temporarily, so it complements other measures.
- ✗
Use CloudWatch alarms to monitor instance launches.
Why it's wrong here
CloudWatch alarms are designed for monitoring metrics and triggering notifications or actions like Auto Scaling, not for enforcing compliance on instance configuration. An alarm could alert you when a launch event occurs, but it cannot inspect tags, VPC placement, or other attributes and cannot prevent or correct the violation. Therefore, it is purely a notification mechanism with no governance capability.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.