Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that all CloudFormation stacks include a specific tag "Environment" with a value of "Production" or "Development". Which approach should be used?

⚠ Common exam trap

Test-takers frequently confuse AWS CloudFormation Guard (a pre-deployment validation tool) with AWS Config (a post-deployment compliance service), or mistakenly believe that IAM policies or SCPs can enforce resource-level tags on CloudFormation stacks, when in fact they only control API request parameters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudFormation Guard to validate that the template includes the required tag with allowed values.

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates before they are used to create or update stacks. By writing a Guard rule that checks for the 'Environment' tag with allowed values of 'Production' or 'Development', you can enforce this requirement at the template level, preventing non-compliant stacks from being deployed. This approach is proactive, catching violations during the authoring or CI/CD pipeline stage rather than after deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS CloudFormation Guard to validate that the template includes the required tag with allowed values.

    Why this is correct

    AWS CloudFormation Guard is a policy-as-code engine that parses and evaluates a template's structure before deployment, allowing you to assert that every resource includes a specific tag key with an allowed value. This validation is proactive, occurring in the CI/CD pipeline prior to stack creation, so non-compliant templates are rejected before any infrastructure exists. Guard rules are written in a simple DSL and can be enforced alongside other template checks, making it the only option that directly inspects the template content rather than relying on API request conditions.

  • ✗

    Apply an IAM policy that requires the tag on all CloudFormation actions.

    Why it's wrong here

    IAM policies can use the `aws:RequestTag` condition key to require that a tag key be present on the `cloudformation:CreateStack` API call, but this only validates the tag on the stack-level request, not the tags on each resource defined inside the template. While IAM can theoretically restrict specific tag values using `StringEquals`, it cannot evaluate the template's resource properties or enforce a rule that every resource has an allowed tag value. As a result, a stack could still be created with untagged resources, and the policy would not detect it unless you separately audit the template.

  • ✗

    Use AWS Config to detect and automatically remediate non-compliant stacks.

    Why it's wrong here

    AWS Config is a detective control that evaluates the configuration of resources only after they have been deployed, so a stack containing resources missing the required tag becomes live before Config can flag it. Even if you configure an automatic remediation action, such as a Systems Manager automation document to add tags, there is an unavoidable lag and the remediation might fail or partially apply tags. Because Config cannot run before the stack exists, it does not prevent non-compliant infrastructure from being created in the first place.

  • ✗

    Create an SCP to deny CloudFormation stacks that do not have the required tag.

    Why it's wrong here

    SCPs are account-level policies that apply to all IAM principals in an organizational unit, and they can deny `cloudformation:CreateStack` based on request tags using `aws:RequestTag` conditions, but they cannot inspect the contents of the CloudFormation template. This means an SCP could require a tag on the stack itself, yet it cannot verify that every resource provisioned by the template carries the required tag with an allowed value. Moreover, SCPs are broad and would affect all stack creation across accounts, making them a blunt instrument that still leaves template-level compliance unchecked.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.