A company's security team requires that all Amazon EC2 instances in a specific AWS account must have the tag 'Environment' set to either 'Production' or 'Test'. Any instance that is launched without this tag or with an invalid value must be automatically terminated within five minutes. Which combination of AWS services can enforce this requirement with minimal manual intervention?
A custom AWS Config rule can evaluate EC2 instances when they are created (configuration change trigger) and invoke an AWS Lambda function to terminate instances lacking the required tag or having an invalid value. This provides continuous compliance enforcement.
Why this answer
AWS Config with a custom rule can evaluate EC2 instances for the required 'Environment' tag with valid values. When a non-compliant instance is detected, AWS Config triggers an AWS Lambda function that terminates the instance within the required five-minute window. This combination provides automated, event-driven enforcement with minimal manual intervention.
Exam trap
The trap here is that candidates may think CloudTrail and CloudWatch Events alone can enforce tag compliance, but they lack the evaluation logic and automated remediation that AWS Config with a custom Lambda rule provides.
How to eliminate wrong answers
Option B is wrong because AWS CloudTrail records API calls and CloudWatch Events can trigger on those events, but they lack native tag validation logic; you would still need a Lambda function to evaluate tag values and terminate instances, making this an incomplete solution. Option C is wrong because AWS Service Catalog enforces compliance at provisioning time through predefined products, but it cannot retroactively terminate instances launched outside the catalog or enforce tag compliance on existing instances. Option D is wrong because Amazon Inspector is a vulnerability assessment service and AWS Systems Manager is for operational management; neither service has the capability to evaluate tags or terminate instances based on tag compliance.