CV0-004 Operations and Support Practice Question
A cloud administrator is standardizing infrastructure provisioning across teams and wants to enforce that all deployed resources carry a mandatory cost-center tag. The administrator needs non-compliant deployments to be rejected automatically across multiple accounts in an AWS Organization. Which control should be implemented?
⚠ Common exam trap
The trap here is treating tag detection tools like AWS Config as preventive controls, when only service control policies can deny the create request outright.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A service control policy applied at the organization root that denies resource creation without the cost-center tag
Service control policies define the permission ceiling for accounts in an AWS Organization and support condition keys such as aws:RequestTag, so a deny statement can block create operations that omit the cost-center tag. Applying it at the root enforces the rule across every account preventively. Config rules, permissions boundaries, and EventBridge remediation act after the fact or per principal and do not block the deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An Amazon EventBridge rule that triggers a Lambda function to delete untagged resources
Why it's wrong here
This is a reactive remediation pattern: the resource is created first and then deleted, causing transient non-compliant state and potential disruption. It requires custom code and per-account configuration, adding operational overhead. The requirement is automatic rejection at deployment time, which this approach does not provide.
- ✗
An AWS Config rule using the required-tags managed rule
Why it's wrong here
AWS Config evaluates resources after they are created and can mark them non-compliant, but evaluation is reactive and does not block the deployment. It provides visibility and can trigger remediation, yet the resource still exists in the meantime. The requirement is to reject non-compliant deployments automatically, which Config alone does not achieve.
- ✓
A service control policy applied at the organization root that denies resource creation without the cost-center tag
Why this is correct
Service control policies set the maximum permissions for accounts in an AWS Organization and can include conditions such as aws:RequestTag to deny create operations lacking the required tag. Applied at the root, the policy covers all accounts and blocks non-compliant deployments at the API layer. This provides preventive, organization-wide enforcement matching the requirement.
- ✗
An IAM permissions boundary attached to each developer role
Why it's wrong here
A permissions boundary limits the maximum permissions a single principal can have but does not evaluate resource tags or enforce tagging policy. It must be attached per role, so it does not scale across multiple accounts in a uniform way. It also cannot express a condition that rejects requests missing a specific tag on the resource.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.