SOA-C02 Security and Compliance Practice Question
A company manages multiple AWS accounts using AWS Organizations. The security team wants to restrict the use of Amazon EC2 instance types to only those that are approved for production workloads (e.g., m5.large, m5.xlarge). The policy should be applied to all member accounts in the organization, and it should prevent any non-approved instance type from being launched. The SysOps administrator should implement this with minimal operational overhead. Which solution should be used?
⚠ Common exam trap
A common mix-up: candidates confuse SCPs with IAM policies, thinking that SCPs grant permissions, but SCPs only act as a guardrail to restrict permissions, and they must be combined with appropriate IAM policies to allow actions; additionally, candidates may choose reactive solutions like AWS Config or EventBridge because they are familiar, but the question explicitly asks for a preventive control with minimal overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an AWS Organizations Service Control Policy (SCP) that denies ec2:RunInstances if the instance type is not in the approved list.
AWS Organizations Service Control Policies (SCPs) can centrally enforce restrictions across all member accounts without requiring per-account configuration. By creating an SCP that denies ec2:RunInstances when the instance type is not in the approved list, the security team can prevent non-approved EC2 instance types from being launched with minimal operational overhead, as SCPs are applied at the organization, OU, or account level and do not require managing IAM policies in each account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM policy in each member account that denies ec2:RunInstances unless the instance type is in the approved list.
Why it's wrong here
An IAM deny policy must be attached to every user or role in the member account, and it does not apply to the account root user, which always retains full permissions unless an SCP blocks it. This requires replicating identical policies across dozens of accounts and using groups or permission boundaries, creating a high risk of drift and missed coverage whenever an account is added or a principal is created. A centralized SCP accomplishes the same restriction with a single policy and cannot be overridden by IAM.
- ✓
Create an AWS Organizations Service Control Policy (SCP) that denies ec2:RunInstances if the instance type is not in the approved list.
Why this is correct
An SCP attached to the organization root, OUs, or individual accounts acts as a preventive guardrail: the deny effect applies to every principal, including the root user. Using a condition such as StringNotEquals on ec2:InstanceType with the approved list, the policy rejects any RunInstances call that uses a non-approved type before the API call can succeed. Because SCPs are inherited and cannot be bypassed by IAM permissions, this gives consistent, low-overhead enforcement across all current and future accounts.
- ✗
Use AWS Config with the managed rule 'ec2-instance-type-check' and an automatic remediation action that terminates non-compliant instances.
Why it's wrong here
AWS Config is a detective service: it evaluates resources periodically or on configuration changes and flags them as non-compliant, but it does not block the RunInstances call. An automatic remediation that terminates the instance adds delays and requires a properly scoped remediation role with permission to terminate instances, as well as steps to handle termination protection or auto-scaling replacement. The rule must also be enabled in every account and region, making it an inefficient distributed control rather than a central preventive one.
- ✗
Use Amazon EventBridge to detect RunInstances API calls and invoke a Lambda function that terminates unapproved instances.
Why it's wrong here
EventBridge can capture RunInstances API calls only if CloudTrail is enabled, and the event is delivered asynchronously after the instance is already running, so the control is not enforced at launch time. Your Lambda termination logic adds a race window in which the unauthorized instance is live, and if the function errors or lacks the termination permission, the control silently fails. This approach is custom code, not a policy, and may also attempt to terminate short-lived instances that already shut down before the Lambda runs.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.