Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO AWS services can be used to enforce that specific resource types (e.g., EC2 instances) are tagged with a 'CostCenter' tag? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations tag policies

AWS Config can evaluate resource tagging and AWS Organizations can use tag policies. IAM is for permissions, not enforcement; CloudFormation can be used but not for existing resources; Service Catalog is for provisioning, not enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Organizations tag policies

    Why this is correct

    AWS Organizations tag policies are a centralized policy type that define which tag keys and values are allowed on resources across all accounts in the organization. Attached to the root, an OU, or an account, they act as a preventive guardrail during resource creation and modification, so a resource that is tagged outside the allowed rules can be denied. This makes them the native service for enforcing specific tags organization-wide.

  • ✗

    AWS Service Catalog

    Why it's wrong here

    AWS Service Catalog lets you create, manage, and curate a catalog of approved products, usually CloudFormation templates, that users can provision on demand. While you can define default tags on provisioned products, Service Catalog only governs the products it deploys; it does not inspect, enforce, or require tags on arbitrary or existing resources outside its catalog. Its purpose is to control which services are available, not to enforce tagging standards across accounts.

  • ✓

    AWS Config

    Why this is correct

    AWS Config provides both managed rules, such as required-tags, and custom Lambda-backed rules that periodically evaluate resource configurations for tag compliance. When a resource lacks a required tag, Config records a noncompliant result and can optionally trigger Systems Manager automation to remediate the tag. This is a powerful detective and corrective control, but it does not prevent the noncompliant resource from being created in the first place.

  • ✗

    AWS CloudFormation

    Why it's wrong here

    AWS CloudFormation can apply stack-level tags to all resources it creates, and templates can define Tags properties on individual resources, which is useful for ensuring newly provisioned resources get consistent tags. However, CloudFormation only influences resources it manages and only at creation time; it has no mechanism to audit or enforce tagging on resources created outside a stack or on pre-existing resources. It is a provisioning tool, not a tag compliance enforcement service.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM controls which principals are allowed to perform actions, and you can use condition keys like aws:RequestTag or aws:TagKeys to restrict tagging operations on individual API calls. But IAM cannot define a required set of tags for every resource, nor can it deny an action simply because a resource lacks a particular tag after creation—it only evaluates the request, not the resulting resource state. Therefore IAM is a permission boundary, not an enforcement mechanism for tag compliance.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.