SOA-C02 Security and Compliance Practice Question
A company requires that all Amazon EC2 instances launched in its AWS account must have termination protection enabled. The SysOps administrator needs to automatically remediate any instance launched without termination protection. The solution should use AWS managed services without custom scripts. Which AWS service should be used?
⚠ Common exam trap
Many exam-takers confuse AWS Config's detection-only capability with its auto-remediation feature, or assume that IAM policies can enforce instance-level attributes at launch time, when in fact IAM conditions like 'ec2:DisableApiTermination' are not supported for the RunInstances action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure AWS Config with a managed rule 'ec2-termination-protection-check' and set an auto-remediation action using an AWS Systems Manager Automation document that enables termination protection on the instance.
AWS Config's managed rule 'ec2-termination-protection-check' can detect instances without termination protection, and you can attach an auto-remediation action using an AWS Systems Manager Automation document (e.g., AWS-EnableTerminationProtection) to automatically enable termination protection on noncompliant instances. This solution uses only AWS managed services and requires no custom scripts, meeting the company's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure AWS Config with a managed rule 'ec2-termination-protection-check' and set an auto-remediation action using an AWS Systems Manager Automation document that enables termination protection on the instance.
Why this is correct
AWS Config's managed rule ec2-termination-protection-check continuously evaluates each EC2 instance against the required configuration, flagging any instance without termination protection as non-compliant. When non-compliance is detected, the associated auto-remediation action invokes an AWS Systems Manager Automation document, such as AWS-EnableEC2TerminationProtection, which calls the ModifyInstanceAttribute API to enable DisableApiTermination on the instance. This serverless, event-driven workflow automatically corrects drift without custom scripts or manual intervention, fully satisfying the company's requirement for automatic remediation.
- ✗
Use Amazon EC2 Auto Scaling to automatically apply termination protection to all launched instances.
Why it's wrong here
Amazon EC2 Auto Scaling provides instance protection for Auto Scaling groups through the instance-protection setting, which prevents instances from being terminated during a scale-in event. However, this is a distinct mechanism that only applies to instances that are part of an Auto Scaling group; it does not enable the EC2 termination protection flag (DisableApiTermination) on instances, and it has no effect on instances launched directly, via other AWS services, or outside a scaling group. Since the requirement applies to all EC2 instances regardless of how they were launched, Auto Scaling cannot serve as a general enforcement mechanism.
- ✗
Enable AWS Trusted Advisor to send notifications when instances lack termination protection, and have administrators manually fix them.
Why it's wrong here
AWS Trusted Advisor does offer a cost-optimization check for underutilized instances and a separate check for EC2 instances with low utilization, but it does not include a specific check for termination protection. Even Trusted Advisor's security checks only identify potential issues and provide recommendations; they never perform remediation. Requiring administrators to manually review notifications and fix non-compliant instances contradicts the explicit mandate for automatic remediation, and it also introduces delay and the possibility of human error in a process that should be fully automated.
- ✗
Create an IAM policy that denies the RunInstances action unless termination protection is enabled.
Why it's wrong here
IAM policies cannot reserve or enforce the termination protection setting because the RunInstances API does not support a condition key such as ec2:DisableApiTermination. While ec2:DisableApiTermination is a valid resource-level permission for actions like ModifyInstanceAttribute, the RunInstances action does not expose that parameter for IAM condition evaluation, so there is no way to require it at launch or to deny a request purely because termination protection was not enabled. Furthermore, even if a policy could deny RunInstances, users could potentially launch instances through services like Auto Scaling or AWS CloudFormation that launch EC2 instances on their behalf, making an IAM-only approach brittle and incomplete.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to enforce that all Amazon EC2 instances launched in the AWS account must have a specific termination protection setting enabled. The SysOps administrator needs to automatically remediate any instances that are launched without termination protection. Which AWS service should be used to achieve this?
medium- A.AWS Config with a managed rule ec2-instance-no-public-ip and an SSM Automation remediation.
- ✓ B.AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.
- C.Amazon Inspector to scan instances and trigger a remediation action.
- D.AWS Systems Manager Patch Manager to apply a policy for termination protection.
Why B: AWS Config can evaluate resources against desired configurations using managed or custom rules. A custom AWS Config rule can invoke a Lambda function to check if termination protection is enabled on EC2 instances and automatically enable it if missing, providing the required remediation. This approach directly addresses the requirement to enforce termination protection on all launched instances.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.