An organization needs to enforce that all Amazon EC2 instances launched in a specific AWS account are created from a baseline Amazon Machine Image (AMI) that includes required security patches. The AMI ID is ami-0abcdef1234567890. What is the MOST efficient way to enforce this requirement?
An IAM policy can use the ec2:ImageId condition key to deny ec2:RunInstances for any AMI that is not the approved one. Because IAM policies are evaluated during API authorization, this acts as a hard, pre-emptive block: the request is denied by AWS before any instance resource is created. This is a true preventive control and meets the organization's enforcement requirement directly. To implement it, add a statement with Effect: Deny, Action: ec2:RunInstances, and Condition: StringNotEquals on the ec2:ImageId key.
Why this answer
An IAM policy with a condition that denies ec2:RunInstances unless the AMI ID matches the approved one (ami-0abcdef1234567890) prevents non-compliant instances from being launched at all. This is the most efficient approach as it enforces the requirement proactively at the API level, avoiding the need for reactive detection or termination.
Exam trap
The trap here is that candidates often choose reactive solutions (like AWS Config or Lambda) because they seem more flexible, but the question asks for the 'MOST efficient' way, which is preventive enforcement via IAM policies at the API level.
How to eliminate wrong answers
Option A is wrong because AWS Config rules can mark non-compliant instances and trigger remediation (e.g., termination), but this is reactive—instances are launched before being detected and terminated, which wastes resources and may cause disruption. Option B is wrong because an AWS Lambda function triggered by EC2 launch events (via CloudTrail or EventBridge) also reacts after the instance is launched, leading to unnecessary resource consumption and potential race conditions. Option C is wrong because AWS CloudTrail only logs API calls for auditing and alerting; it cannot enforce or prevent the launch of non-compliant instances, making it purely detective and not preventive.