Courseiva

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company has a multi-account environment with AWS Organizations. The security team wants to enforce that all EC2 instances launched in any account must have a specific tag key 'CostCenter'. Which approach should be used?

⚠ Common exam trap

Test-takers frequently confuse detective controls (like AWS Config) with preventive controls (like SCPs), or assume that IAM policies in each account are sufficient for centralized enforcement, overlooking the fact that SCPs are the only mechanism that can enforce policies across all accounts in an organization without being overridden.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Service Control Policy (SCP) that denies ec2:RunInstances unless the request includes the required tag.

A Service Control Policy (SCP) applied at the AWS Organizations root or OU level can centrally deny the ec2:RunInstances action unless the request includes the required 'CostCenter' tag. This enforces the tagging requirement across all accounts in the organization without needing per-account IAM policies, and it cannot be overridden by account administrators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM policy in each account that requires the tag for ec2:RunInstances.

    Why it's wrong here

    An IAM policy in each account is per-account and can be altered or omitted, so it cannot enforce the tag across the organisation. IAM policies are tempting because they govern RunInstances permissions, but organisation-wide enforcement requires a service control policy in AWS Organizations.

  • ✓

    Use a Service Control Policy (SCP) that denies ec2:RunInstances unless the request includes the required tag.

    Why this is correct

    An SCP denying ec2:RunInstances unless aws:RequestTag/CostCenter is present enforces the requirement centrally across every account in the organisation, satisfying the multi-account constraint without per-account tooling. Because SCPs gate IAM permissions at the organisation level, no principal in any member account can bypass the tag condition.

  • ✗

    Use AWS Config rules to detect untagged instances and trigger an AWS Lambda function to tag them.

    Why it's wrong here

    AWS Config rules detect non-compliance after the instance exists and Lambda then remediates, so untagged instances are still created. Detection-and-remediation is tempting for drift control, but the stem requires enforcement at launch, which an SCP with a tag condition provides.

  • ✗

    Configure the EC2 service to automatically add the tag to all instances.

    Why it's wrong here

    EC2 cannot automatically add a tag key to every instance; default tagging applies only where configured and does not enforce presence at launch. Automatic tagging is tempting as a convenience, but the requirement is prevention of untagged launches, which needs an SCP condition.

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.