Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

An organization has a multi-account AWS environment using AWS Organizations. The security team needs to ensure that no Amazon EC2 instances are launched without an IAM instance profile that includes a specific role. Which preventive control should be implemented?

⚠ Common exam trap

It's easy for candidates to confuse the condition key `iam:InstanceProfile` (which is correct for IAM instance profiles) with `ec2:InstanceProfile` (which does not exist), leading candidates to choose Option C, and also mistaking detective controls like AWS Config for preventive controls, as in Option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an SCP that denies ec2:RunInstances when the condition iam:InstanceProfile is not set to the required profile ARN.

AWS Organizations Service Control Policies (SCPs) can be applied to all accounts in the organization to prevent actions across all principals. By using the `iam:InstanceProfile` condition key with the `ec2:RunInstances` action, the SCP denies the launch of any EC2 instance that does not have the required IAM instance profile attached. This is a preventive control that blocks the action before it occurs, ensuring compliance across the entire multi-account environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an SCP that denies ec2:RunInstances when the condition iam:InstanceProfile is not set to the required profile ARN.

    Why this is correct

    This SCP is correct because it applies at the organization level to all member accounts and uses the global IAM condition key iam:InstanceProfile to require a specific instance profile ARN. The deny rule blocks any ec2:RunInstances call from any principal—user, role, or service—that does not include the required profile in its parameters. The condition key is evaluated exactly and provides a preventive guardrail that cannot be bypassed by user-specific policy exceptions.

  • ✗

    Attach an IAM policy to all users that denies ec2:RunInstances unless an instance profile is specified.

    Why it's wrong here

    This approach is insufficient because user-level IAM policies only govern authenticated users, not IAM roles, service-linked roles, or AWS services that assume roles on your behalf, so an EC2 instance can still be launched without the profile via a role or a service like CloudFormation. More fundamentally, a user policy can be overridden by a role's permissions, and it does not set an organization-wide guardrail. Additionally, maintaining such a policy across every existing and future user is operationally fragile compared to a single SCP at the root.

  • ✗

    Create an SCP that denies ec2:RunInstances when the condition ec2:InstanceProfile is not set.

    Why it's wrong here

    This SCP would fail because there is no service-specific condition key named ec2:InstanceProfile in the EC2 action's condition context; the correct key is the global condition key iam:InstanceProfile. If a policy references an invalid condition key, that condition evaluates to false in the request context, so the deny is not triggered and the action is allowed. Thus, using ec2:InstanceProfile would silently make the SCP ineffective, and the missing condition could not enforce the required instance profile ARN.

  • ✗

    Use AWS Config rule ec2-instance-profile-attached to detect non-compliant instances and automatically terminate them.

    Why it's wrong here

    An AWS Config rule is purely detective: it evaluates launched resources after the fact, and automatic termination requires a separate custom remediation or a Lambda function, meaning no denial occurs at the moment of RunInstances. The required rule only reports non-compliance and cannot by itself prevent the instance from being created. Additionally, automatically terminating instances based on a Config rule is risky because it may disrupt legitimate workloads, has a time delay, and cannot enforce a mandatory profile ARN value, only the presence of a profile.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.