Courseiva
Question 1,669 of 1,660
Design Solutions for Organizational ComplexitymediumMultiple ChoiceObjective-mapped

SAP-C02 Practice Question: Design Solutions for Organizational Complexity

A company uses AWS Organizations with consolidated billing. The finance team needs to track costs by department, which are tagged with 'department' tags. However, some resources are not tagged. The team wants to ensure that all new resources are tagged, and existing untagged resources are identified. What should they do?

⚠ Common exam trap

It's easy for candidates to confuse AWS Config's ability to detect non-compliance with the ability to automatically remediate (e.g., apply tags), or assume that Cost Explorer can enforce tagging, when in fact it only reports on existing tags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a service control policy (SCP) to deny resource creation without the 'department' tag, and use AWS Config rules to detect untagged resources.

It combines two complementary AWS services to solve both requirements. A service control policy (SCP) can deny the creation of any resource that does not include the required 'department' tag, enforcing tagging at the organization level across all accounts. AWS Config rules can then be used to detect existing untagged resources by evaluating resources against a desired tagging configuration, providing visibility into non-compliant resources without automatically modifying them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a service control policy (SCP) to deny resource creation without the 'department' tag, and use AWS Config rules to detect untagged resources.

    Why this is correct

    SCPs prevent creation of untagged resources; Config identifies existing untagged resources.

  • Use AWS Config rules to enforce tagging on existing resources and automatically tag them.

    Why it's wrong here

    Config rules cannot automatically tag; they can only detect.

  • Use AWS Cost Explorer to report on untagged resources.

    Why it's wrong here

    Cost Explorer can report but does not enforce tagging.

  • Create an IAM policy that requires tagging for all actions and attach it to all users.

    Why it's wrong here

    Not all actions support tagging; IAM policies are not account-wide.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.