SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is managing multiple AWS accounts using AWS Organizations. They want to centralize the management of EC2 instances and enforce tagging standards across all accounts. Which TWO approaches should they use?
⚠ Common exam trap
It's easy for candidates to confuse AWS Service Catalog's tagging enforcement as a global solution, not realizing it only applies to products launched through the catalog, not to direct EC2 API calls across accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS CloudFormation StackSets to deploy AWS Config rules across all accounts to check for required tags.
Option A is correct because CloudFormation StackSets can deploy AWS Config rules (e.g., required-tags) across all accounts in an AWS Organization from a single administrator account, providing centralized, continuous detection of non-compliant EC2 instances and their tags. Option D is correct because an SCP attached to the organization's root or OUs can enforce tagging standards preventively by denying ec2:RunInstances when the required tag keys/values are absent (using conditions such as aws:RequestTag and aws:TagKeys), blocking non-compliant launches across all member accounts. Option B is not correct because Service Catalog constraints (e.g., TagOptions) only apply to products launched through the catalog, not to all EC2 instances across accounts. Option C is not correct because AWS Resource Access Manager shares resources such as subnets, Transit Gateways, and Route 53 Resolver rules, not tagging policies. Option E is not correct because Auto Scaling lifecycle hooks pause instances during launch/termination for custom actions and do not enforce or automatically add tags to meet organization-wide tagging standards.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS CloudFormation StackSets to deploy AWS Config rules across all accounts to check for required tags.
Why this is correct
AWS Config rules deployed via CloudFormation StackSets provide continuous, account-wide tag compliance evaluation, satisfying the requirement to enforce tagging standards centrally. StackSets handle cross-account deployment through AWS Organizations, while Config detects non-compliant EC2 instances and can trigger remediation, giving the governance mechanism the scenario demands.
- ✗
Use AWS Service Catalog to enforce tagging on EC2 products.
Why it's wrong here
Service Catalog governs provisioning of approved products through portfolios, so tags apply only when users launch through it; EC2 instances created by other means escape enforcement. It is tempting because Service Catalog does constrain launches and can attach tags, but it is a self-service catalogue, not an organisation-wide tagging policy engine.
- ✗
Use AWS Resource Access Manager to share a tagging policy across accounts.
Why it's wrong here
AWS Resource Access Manager shares resources such as subnets and Transit Gateways across accounts; it does not distribute or enforce tag policies. Tag policies are an AWS Organizations feature. RAM would be correct for sharing a VPC subnet or resolver rule between accounts.
- ✓
Apply a service control policy (SCP) that denies ec2:RunInstances if the required tags are not specified.
Why this is correct
An SCP in AWS Organizations propagates to every member account, so a deny on ec2:RunInstances without the mandated tags enforces tagging standards centrally at the API level, regardless of who launches instances. This satisfies the cross-account enforcement constraint without per-account IAM policy duplication.
- ✗
Use EC2 Auto Scaling lifecycle hooks to add tags automatically.
Why it's wrong here
Auto Scaling lifecycle hooks pause instances during launch or termination for custom actions; they do not add tags, and they act only on Auto Scaling groups, leaving standalone EC2 instances untagged. Tempting because hooks run automation at launch time, but that mechanism is for invoking Lambda or EventBridge actions, not tag enforcement.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.