SCS-C02 Infrastructure Security Practice Question
A company uses AWS CloudFormation to deploy infrastructure. The security team needs to ensure that all CloudFormation stacks include a specific tag with a value that complies with corporate policies. Which AWS service can enforce this requirement?
⚠ Common exam trap
Candidates often assume AWS Config can enforce tagging because it can detect and remediate non-compliant tags, but Config is a detective control, not a preventive one, and cannot block stack creation without the required tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Service Catalog
AWS Service Catalog allows administrators to create and manage a portfolio of approved products (e.g., CloudFormation templates) with predefined constraints. One such constraint is a tag option, which enforces that every provisioned product (i.e., CloudFormation stack) includes a specific tag key and value, ensuring compliance with corporate policies. This is the only service among the options that can directly enforce mandatory tagging on CloudFormation stacks at provisioning time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a detective control that continuously evaluates recorded AWS resource configurations against desired policies using managed or custom rules. It can detect resources that are missing required tags and even invoke automated remediation actions, but it does not intercept CloudFormation stack creation or prevent non-compliant resources from being provisioned. Because the deployment has already occurred before Config can report or react, it cannot be used to enforce tag policies on infrastructure as it is being created.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
IAM policies can restrict API actions and require that principals include particular tags in their request using condition keys like aws:RequestTag, but they cannot mandate a comprehensive tagging policy for every resource created by CloudFormation templates. The service role or user identity may be forced to tag the stack itself, yet resources such as EC2 instances or S3 buckets launched from the template inherit only what the template defines, not arbitrary enforced values. Therefore, IAM is insufficient as a preventive mechanism for enforcing specific tag values on all generated resources.
- ✓
AWS Service Catalog
Why this is correct
AWS Service Catalog acts as a governed provisioning layer for CloudFormation templates, allowing administrators to create portfolios of approved products and attach tag options, stack constraints, and IAM roles to those products. When a user provisions a product, Service Catalog automatically applies the configured tag options to the stack and all resources within it, and can reject deployment if required tags are missing. This makes it the only option here that prevents non-compliant infrastructure from being created while still allowing users to deploy via CloudFormation.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an auditing service that records API calls made by users, roles, and services, capturing details such as who created or updated a CloudFormation stack and what tags were changed. It can help investigate after the fact why a resource lacks required tags, but it has no enforcement action and cannot block or modify infrastructure during provisioning. It is purely a log or visibility control, so it offers no preventive or corrective capability aligned with the requirement.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.