Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

An organization needs to enforce that all Amazon EC2 instances launched in a specific AWS account are created from a baseline Amazon Machine Image (AMI) that includes required security patches. The AMI ID is ami-0abcdef1234567890. What is the MOST efficient way to enforce this requirement?

⚠ Common exam trap

Many exam-takers choose reactive solutions (like AWS Config or Lambda) because they seem more flexible, but the question asks for the 'MOST efficient' way, which is preventive enforcement via IAM policies at the API level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an IAM policy that denies the ec2:RunInstances action unless the AMI ID matches the approved one.

An IAM policy with a condition that denies ec2:RunInstances unless the AMI ID matches the approved one (ami-0abcdef1234567890) prevents non-compliant instances from being launched at all. This is the most efficient approach as it enforces the requirement proactively at the API level, avoiding the need for reactive detection or termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Config rule to mark non-compliant instances and automatically terminate them.

    Why it's wrong here

    AWS Config is a detective, not a preventive, control. While a Config rule can mark instances launched with the wrong AMI as non-compliant and you can attach a remediation action to terminate them, the evaluation occurs after the instance is already running, and the remediation is asynchronous — leaving a window where the non-compliant resource exists and may execute workloads. This approach cannot block the ec2:RunInstances call at the API layer, so it fails the organization's requirement to "enforce" the AMI restriction.

  • ✗

    Use an AWS Lambda function that is triggered by EC2 launch events to terminate non-compliant instances.

    Why it's wrong here

    An EventBridge or CloudTrail-triggered Lambda function that terminates non-compliant instances is reactive, operating after the launch request has already succeeded. There is an inherent delay between the EC2 creation event and invocation, during which the instance can accept user data, join networks, or execute startup scripts, and if the Lambda lacks permissions or fails, the instance persists. Additionally, terminating an instance is not the same as denying the action; it creates event noise and leaves behind associated resources like EBS volumes and ENIs unless additional cleanup logic is written, making this a fragile enforcement mechanism.

  • ✗

    Use AWS CloudTrail to monitor and alert on any instance launched with a different AMI.

    Why it's wrong here

    CloudTrail records the ec2:RunInstances API call as a JSON event, and you can configure a metric filter or an EventBridge rule to alert when an unsupported AMI is used, but this is purely observational — it does not alter the authorization decision. The instance is launched and starts running before any alarm is sent, so it cannot serve as an enforcement control. Moreover, parsing the CloudTrail event to extract the ImageId and compare it to an approved list requires custom logic, and the result is still only a notification, not a denial of the request.

  • ✓

    Use an IAM policy that denies the ec2:RunInstances action unless the AMI ID matches the approved one.

    Why this is correct

    An IAM policy can use the ec2:ImageId condition key to deny ec2:RunInstances for any AMI that is not the approved one. Because IAM policies are evaluated during API authorization, this acts as a hard, pre-emptive block: the request is denied by AWS before any instance resource is created. This is a true preventive control and meets the organization's enforcement requirement directly. To implement it, add a statement with Effect: Deny, Action: ec2:RunInstances, and Condition: StringNotEquals on the ec2:ImageId key.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.