Courseiva

SCS-C02 Management and Security Governance Practice Question

A company has a multi-account AWS environment managed with AWS Organizations. The security team wants to ensure that no EC2 instance in any account can be launched without a specific tag 'CostCenter'. The team has created a Service Control Policy (SCP) that denies the ec2:RunInstances action if the request does not include the tag 'CostCenter'. However, they find that instances are still being launched without the tag in some accounts. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The accounts launching instances without tags are the management account.

The most likely reason is that the accounts launching instances without the tag are the management account. Service Control Policies (SCPs) do not affect the management account in AWS Organizations; they only apply to member accounts. Therefore, if the security team is testing from the management account, the SCP denying ec2:RunInstances without the 'CostCenter' tag will not be enforced. Option A is incorrect because 'aws:RequestTag' is the correct condition key for tagging requests, not 'aws:ResourceTag'. Option C is incorrect because SCPs work by denying actions, not by requiring explicit allows. Option D is incorrect because the SCP would still prevent unauthorized launches even without an explicit allow. The issue is specifically that SCPs do not apply to the management account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SCP uses the wrong condition key; it should use 'aws:ResourceTag' instead.

    Why it's wrong here

    For ec2:RunInstances, tags supplied in the launch request are not yet attributes of an existing resource, so aws:ResourceTag has nothing to evaluate. The correct condition key is aws:RequestTag, which inspects the tag keys and values submitted at launch time. Using aws:ResourceTag would cause the SCP to either never match the intended condition or fail to prevent untagged instance creation.

  • ✓

    The accounts launching instances without tags are the management account.

    Why this is correct

    In AWS Organizations, the management account is explicitly exempt from all SCPs; SCPs can only restrict access for member accounts. If the SCP is attached at the root or to the relevant OUs and untagged instances still appear, the launches must be originating from the management account, whose principals are not evaluated against any SCP and therefore retain full permissions.

  • ✗

    The SCP does not include an explicit allow for the action.

    Why it's wrong here

    SCPs use an implicit-allow model: every action is permitted unless an explicit Deny statement in the SCP matches the request. An SCP does not need an explicit Allow, and an Allow in an SCP cannot grant permissions because SCPs only act as filters on the identity policies of member accounts. Therefore, the absence of an explicit Allow is not a valid reason for untagged instances being launched.

  • ✗

    The SCP is not attached to the organizational units containing the accounts.

    Why it's wrong here

    If the SCP were not attached to the OUs containing the affected member accounts, those accounts would not see the deny effect at all. However, the observed behavior—untagged launches only in the management account—indicates the SCP is actually attached and applying correctly to member accounts. The real cause is the management account's exemption from SCPs, not a gap in OU attachment.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.