Deploy a restrictive instance template with Lambda and EventBridge to isolate instances carrying the isolation tag
A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company needs an automated process across all AWS accounts to isolate any compromised Amazon EC2 instances when the instances receive a specific tag. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
85% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Network isolation requires removing the instance's security groups and replacing them with a group that has no inbound or outbound rules, which is what the Lambda in option E does, leaving the compromised instance unable to send or receive traffic (E). Because the automation must exist in every account, distributing the template with StackSets is what makes it available organization-wide (A). Option B's SCP with a condition on aws:RequestTag/isolation blocks ec2:* calls rather than isolating the instance, and C attaches such an SCP at the organization root, so together they do not isolate anything.
To automatically isolate compromised EC2 instances across all accounts when a specific tag is applied, standardize the behavior with a CloudFormation template distributed by CloudFormation StackSets to every account (A). The template creates an EC2 instance role with no IAM policies and a security group with no inbound or outbound rules, plus a Lambda function that attaches that role and swaps existing security groups for the restrictive one, with an EventBridge rule invoking it when the isolation tag appears on an instance. Isolation means cutting network traffic to and from the instance, not merely preventing API calls on it.
Using an SCP to deny ec2:* when the isolation tag is not present (B) — this removes API permissions on the tagged instance but does nothing to stop traffic to and from it; xdkonorek2 put it precisely, isolating the instance does not mean don't touch it with AWS actions, it means blocking traffic. Attaching that SCP at the organization root (C) — this applies a blanket API restriction rather than isolating the compromised instance, so it would break legitimate automation without containing the threat. A security group with an explicit Deny rule on all traffic (option D's description) is also invalid because security groups support only allow rules.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Isolation in this context means blocking network traffic to and from the compromised instance, not removing its IAM permissions. The CloudFormation template (deployed to every account via StackSets, option A) provisions an EC2 instance role with no IAM policies and, critically, a security group with no inbound rules and no outbound rules. The Lambda function attaches that role to the instance and replaces its existing security groups with the restrictive one, which leaves the instance unable to send or receive any traffic and thereby contains the compromise. An EventBridge rule invokes the Lambda when the specific isolation tag is applied, making the response automated.Why the Other Options Are Wrong
B creates an SCP with a deny on ec2:* conditioned on aws:RequestTag/isolation being false. This restricts AWS API actions on the instance but leaves its network connectivity intact, so the compromised instance can still communicate with an attacker; as several commenters noted, isolating the instance is about blocking traffic, not about blocking API calls. C attaches that SCP to the organization root, which imposes the API restriction broadly across the organization without isolating the tagged instance, breaking legitimate automation while failing to contain the threat. D describes a security group with an explicit deny rule, which cannot exist because security groups support only allow rules, and its Lambda only adds a network ACL rather than enforcing the isolation through security groups. A and E are correct.Community Comment Notes
Community voted A,E (85), with B,C a 15 percent minority. Commenters noted the awkward wording and explained the intended meaning: the deny-on-ec2 actions in B and C do not isolate an instance, whereas E's replacement of security groups with a group that has no inbound or outbound rules does, and xdkonorek2 articulated that distinction directly.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →