Courseiva

Enforcing EC2 Tagging at Launch with IAM Policy Conditions

A security engineer needs to ensure that all EC2 instances launched in a development account are tagged with a cost center. What is the most effective way to enforce this?

⚠ Common exam trap

Test-takers frequently choose AWS Config (Option A) because it is a common governance tool, but they miss that Config only detects non-compliance after the fact, whereas IAM policies provide preventive enforcement at the API level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an IAM policy that denies ec2:RunInstances unless the request includes the cost center tag

Using an IAM policy with a condition key (e.g., `aws:RequestTag`) that denies `ec2:RunInstances` unless the `cost center` tag is specified in the API call enforces tagging at launch time. This prevents any untagged instance from being created, providing proactive enforcement rather than reactive detection or remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config to detect untagged instances and send alerts

    Why it's wrong here

    AWS Config is a detective service: it continuously evaluates the resource state against rules, such as whether the cost-center tag is present on EC2 instances, and can publish findings to Amazon SNS for alerts. However, it only reports on noncompliant resources after they already exist; it does not intercept the ec2:RunInstances API call, so it cannot prevent an untagged instance from being launched in the first place.

  • ✗

    Use AWS Systems Manager to tag instances after launch

    Why it's wrong here

    AWS Systems Manager can automate tagging after launch using an Automation runbook, maintenance window, or a Lambda target, but that is inherently a reactive remediation step. By the time SSM applies the tag, a period of untagged operation has already elapsed, and the action does not stop the original launch request; it only patches the state after the fact. This cannot ensure that every EC2 instance is created with the required tag from the moment it exists.

  • ✗

    Create a tag policy in AWS Organizations requiring the cost center tag

    Why it's wrong here

    AWS Organizations tag policies define the allowed tag keys and values for resources in your accounts, but they act as a compliance mechanism that relies on AWS Config to detect and report violations; they do not evaluate or block the RunInstances API request. Tag policies are not IAM policies or service control policies, so a user can still successfully launch an instance without the required tag, and the policy only flags the resource as noncompliant after creation.

  • ✓

    Use an IAM policy that denies ec2:RunInstances unless the request includes the cost center tag

    Why this is correct

    An IAM policy can explicitly deny ec2:RunInstances when a condition key such as ec2:RequestTag/cost-center is absent from the API request—for example, by using a Null condition set to true. Because IAM policies are evaluated before the API call is executed, any launch attempt that omits the cost-center tag is immediately rejected, before any instance is created. This is a true preventive control and is the only listed option that stops the launch itself.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.