Deploy a restrictive instance template with Lambda and EventBridge to isolate instances carrying the isolation tag

Answer Correct answer: A, E — distribute the isolation template with StackSets and replace the tagged instance's security groups with a no-rules group.

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company needs an automated process across all AWS accounts to isolate any compromised Amazon EC2 instances when the instances receive a specific tag. Which combination of steps will meet these requirements? (Choose two.)

  1. Use AWS CloudFormation StackSets to deploy the CloudFormation stacks in all AWS accounts. Correct Answer
  2. Create an SCP that has a Deny statement for the ec2:* action with a condition of "aws:RequestTag/isolation": false.
  3. Attach the SCP to the root of the organization.
  4. Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has an explicit Deny rule on all traffic. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to add a network ACL. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance.
  5. Create an AWS CloudFormation template that creates an EC2 instance role that has no IAM policies attached. Configure the template to have a security group that has no inbound rules or outbound rules. Use the CloudFormation template to create an AWS Lambda function that attaches the IAM role to instances. Configure the Lambda function to replace any existing security groups with the new security group. Set up an Amazon EventBridge rule to invoke the Lambda function when a specific tag is applied to a compromised EC2 instance. Correct Answer

Community Votes

AE
85%
BC
15%

85% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Network isolation requires removing the instance's security groups and replacing them with a group that has no inbound or outbound rules, which is what the Lambda in option E does, leaving the compromised instance unable to send or receive traffic (E). Because the automation must exist in every account, distributing the template with StackSets is what makes it available organization-wide (A). Option B's SCP with a condition on aws:RequestTag/isolation blocks ec2:* calls rather than isolating the instance, and C attaches such an SCP at the organization root, so together they do not isolate anything.

To automatically isolate compromised EC2 instances across all accounts when a specific tag is applied, standardize the behavior with a CloudFormation template distributed by CloudFormation StackSets to every account (A). The template creates an EC2 instance role with no IAM policies and a security group with no inbound or outbound rules, plus a Lambda function that attaches that role and swaps existing security groups for the restrictive one, with an EventBridge rule invoking it when the isolation tag appears on an instance. Isolation means cutting network traffic to and from the instance, not merely preventing API calls on it.

Using an SCP to deny ec2:* when the isolation tag is not present (B) — this removes API permissions on the tagged instance but does nothing to stop traffic to and from it; xdkonorek2 put it precisely, isolating the instance does not mean don't touch it with AWS actions, it means blocking traffic. Attaching that SCP at the organization root (C) — this applies a blanket API restriction rather than isolating the compromised instance, so it would break legitimate automation without containing the threat. A security group with an explicit Deny rule on all traffic (option D's description) is also invalid because security groups support only allow rules.

Community Discussion (10 comments)

Jay_2pt0_1 👍 6 Selected: AE
What a weirdly worded question. I tend to agree with A & E. We need to isolate an EC2 that has a certain tag.
Jordarlu 👍 2 Selected: AE
The B + C means no actions allowed on the tagged EC2 for all accounts in Organizations, but the asking was the needs of the isolation(implying the network isolation) on the tagged EC2; hence, A + E is a good option here..
jamesf 👍 3 Selected: AE
I go for AE isolating the instance should be mean block traffic
trungtd 👍 4 Selected: AE
This CloudFormation template creates the necessary resources: An EC2 instance role with no IAM policies, ensuring the instance cannot perform any actions. A security group with no inbound or outbound rules, effectively isolating the instance from all network traffic. A Lambda function that will be triggered by an EventBridge rule when a specific tag is applied to an EC2 instance. This function will attach the isolated security group to the compromised instance, ensuring it is isolated from any network communication. Combining these steps will provide an automated and consistent approach to isolate compromised EC2 instances across all AWS accounts in the organization.
xdkonorek2 👍 3 Selected: AE
BD is wrong isolating the instance doesn't mean "don't touch it" with aws actions but to block traffic from and to it
seetpt 👍 1 Selected: BC
BC for me
dkp 👍 4 Selected: AE
ill go with AE
Ola2234 👍 1
CE for me. Option D is wrong because we can not use Security Group for an explicit deny rule. Option B is quite misleading with the resourceTagIsolation set to False instead of True.
fdoxxx 👍 3 Selected: BC
in my opinion it could not be AE because we would need a mechanism to apply this template to the right EC2 - I would vote for BC
ogerber 👍 4 Selected: AE
A,E for me

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Isolation in this context means blocking network traffic to and from the compromised instance, not removing its IAM permissions. The CloudFormation template (deployed to every account via StackSets, option A) provisions an EC2 instance role with no IAM policies and, critically, a security group with no inbound rules and no outbound rules. The Lambda function attaches that role to the instance and replaces its existing security groups with the restrictive one, which leaves the instance unable to send or receive any traffic and thereby contains the compromise. An EventBridge rule invokes the Lambda when the specific isolation tag is applied, making the response automated.

Why the Other Options Are Wrong

B creates an SCP with a deny on ec2:* conditioned on aws:RequestTag/isolation being false. This restricts AWS API actions on the instance but leaves its network connectivity intact, so the compromised instance can still communicate with an attacker; as several commenters noted, isolating the instance is about blocking traffic, not about blocking API calls. C attaches that SCP to the organization root, which imposes the API restriction broadly across the organization without isolating the tagged instance, breaking legitimate automation while failing to contain the threat. D describes a security group with an explicit deny rule, which cannot exist because security groups support only allow rules, and its Lambda only adds a network ACL rather than enforcing the isolation through security groups. A and E are correct.

Community Comment Notes

Community voted A,E (85), with B,C a 15 percent minority. Commenters noted the awkward wording and explained the intended meaning: the deny-on-ec2 actions in B and C do not isolate an instance, whereas E's replacement of security groups with a group that has no inbound or outbound rules does, and xdkonorek2 articulated that distinction directly.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide