easyMultiple Choice
How to Handle an Untagged Resource Alert: Apply Tags Without Disruption
A company has a policy that all cloud resources must be tagged with 'CostCenter' and 'Project' tags. The cloud operations team uses a monitoring tool to alert when untagged resources are created. The team receives an alert for a new EC2 instance that lacks the required tags. The instance was launched two hours ago by a DevOps engineer who is on leave. The instance is critical for production. What should the administrator do to resolve the compliance violation?
Quick Answer
The correct action is to apply the required tags to the existing EC2 instance using the cloud provider’s console or CLI, because tagging is a metadata operation that does not affect the running state of a resource. This resolves the untagged cloud resource compliance alert without disrupting the critical production workload, since stopping or terminating the instance would cause unnecessary downtime. On the CompTIA Cloud+ CV0-004 exam, this scenario tests your understanding of resource governance and the principle of least disruption—you must prioritize business continuity over re-creating resources. A common trap is assuming you must rebuild the instance to enforce tagging, but cloud providers allow retroactive tagging on existing resources. Remember the memory tip: “Tag, don’t drag”—apply tags in place rather than dragging the instance offline.
⚠ Common exam trap
A common mistake is to assume that a compliance violation due to missing tags requires terminating and recreating the resource. In reality, tags can be applied to existing instances without disruption, as they are metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the required tags to the existing instance using the cloud provider's console or CLI.
The compliance violation is the absence of required tags, not a problem with the instance itself. The administrator can use the AWS Management Console, CLI (e.g., `aws ec2 create-tags`), or SDK to apply the 'CostCenter' and 'Project' tags to the existing EC2 instance without disrupting its operation. This resolves the alert and maintains production continuity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Terminate the instance immediately and launch a new one with proper tags.
Why it's wrong here
Terminating the instance destroys a critical production workload to fix a metadata gap that tagging the running resource would resolve without downtime. Termination is appropriate only when the resource is disposable, non-critical, or itself the security threat.
- ✓
Apply the required tags to the existing instance using the cloud provider's console or CLI.
Why this is correct
Applying the missing CostCenter and Project tags directly to the running EC2 instance via the console or CLI remediates the violation without disrupting the production workload. Tagging is a metadata operation on the resource, requiring no restart or redeployment, so the critical instance stays available while satisfying the policy's tagging requirement.
- ✗
Ignore the alert because the instance is critical and the engineer will fix it when back.
Why it's wrong here
Ignoring the alert leaves the instance non-compliant with the mandatory tagging policy, and the absent engineer cannot be relied upon to remediate it. Tagging the running instance directly resolves the violation without disrupting production; ignoring suits only transient, non-critical, self-correcting gaps.
- ✗
Modify the tag policy to exempt instances launched by senior engineers.
Why it's wrong here
Exempting senior engineers' instances changes the policy itself rather than remediating the untagged resource, so the EC2 instance remains non-compliant and the control is weakened. Policy exemptions are appropriate only when a documented, approved exception genuinely justifies them.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CV0-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization requires that all cloud resources be tagged with the cost center and environment (e.g., production, development). A compliance checker runs weekly to report untagged resources. The cloud administrator notices that newly created resources are often missing tags. What is the most effective long-term solution?
easy- ✓ A.Configure a cloud governance policy that prevents resource creation without required tags.
- B.Create a custom dashboard to show untagged resources.
- C.Run a script daily to tag any untagged resources.
- D.Send an email reminder to all users about tagging policies.
Why A: The most effective long-term solution is to prevent non-compliant resource creation in the first place, which is what a governance policy (e.g., AWS Organizations SCP, Azure Policy, or GCP Org Policy) does by denying creation of resources without required tags. Detection and remediation after the fact are reactive and leave gaps. Prevention enforces the standard at the control plane, so untagged resources never exist.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.