Use an SCP to require the CostCenter tag, a tag policy for valid values, and update the script to fix noncompliant resources

Answer Correct answer: A — require the tag key with an SCP, restrict values with a tag policy, and have the script correct noncompliant resources.

A company uses an organization in AWS Organizations to manage its 500 AWS accounts. The organization has all features enabled. The AWS accounts are in a single OU. The developers need to use the CostCenter tag key for all resources in the organization's member accounts. Some teams do not use the CostCenter tag key to tag their Amazon EC2 instances. The cloud team wrote a script that scans all EC2 instances in the organization's member accounts. If the EC2 instances do not have a CostCenter tag key, the script will notify AWS account administrators. To avoid this notification, some developers use the CostCenter tag key with an arbitrary string in the tag value. The cloud team needs to ensure that all EC2 instances in the organization use a CostCenter tag key with the appropriate cost center value. Which solution will meet these requirements?

  1. Create an SCP that prevents the creation of EC2 instances without the CostCenter tag key. Create a tag policy that requires the CostCenter tag to be values from a known list of cost centers for all EC2 instances. Attach the policy to the OU. Update the script to scan the tag keys and tag values. Modify the script to update noncompliant resources with a default approved tag value for the CostCenter tag key. Correct Answer
  2. Create an SCP that prevents the creation of EC2 instances without the CostCenter tag key. Attach the policy to the OU. Update the script to scan the tag keys and tag values and notify the administrators when the tag values are not valid.
  3. Create an SCP that prevents the creation of EC2 instances without the CostCenter tag key. Attach the policy to the OU. Create an IAM permission boundary in the organization's member accounts that restricts the CostCenter tag values to a list of valid cost centers.
  4. Create a tag policy that requires the CostCenter tag to be values from a known list of cost centers for all EC2 instances. Attach the policy to the OU. Configure an AWS Lambda function that adds an empty CostCenter tag key to an EC2 instance. Create an Amazon EventBridge rule that matches events to the RunInstances API action with the Lambda function as the target.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Only option A addresses all three failure modes, which is why each element is needed (A). The SCP prevents the tag key from being missing entirely. The tag policy is the only control that can validate the tag's value against a known list, because neither an SCP nor an IAM permission boundary can restrict a string value the way a tag policy can. And updating the script to both inspect values and fix noncompliant resources closes the loop, since a resource created before the controls existed still has to be corrected. f4b18ba and Srikantha both identified the division of labour between the SCP and the tag policy.

Developers are tagging EC2 instances with arbitrary CostCenter values to silence the notification script, so the tag key is present but the value is meaningless. Three controls are needed together. An SCP prevents the creation of EC2 instances without the CostCenter tag key, enforcing the requirement at creation. An Organizations tag policy restricts the CostCenter tag to values from the known list of cost centers, so an arbitrary string is rejected. Finally, the existing script is updated to inspect both tag keys and tag values and to modify noncompliant resources with a default approved value rather than merely notifying administrators.

Attaching only the SCP that requires the CostCenter tag key and updating the script to notify administrators when tag values are invalid (B) — this does nothing about the arbitrary values: the SCP only requires the key to be present, so a developer can keep supplying any string and simply receive a notification, and notifying does not correct the resource. Adding an IAM permission boundary restricting CostCenter tag values (C in option C) — a permissions boundary caps which API actions a principal may call and cannot constrain the value of a tag on a resource, so it cannot enforce a valid-value list. Creating a tag policy plus a Lambda that adds an empty CostCenter tag and an EventBridge rule on RunInstances (D) — adding an empty tag value to a new instance does not validate against the list and does not remediate existing noncompliant instances, so the arbitrary-value workaround continues.

Community Discussion (3 comments)

f4b18ba 👍 5 Selected: A
Service Control Policy (SCP): Creating an SCP ensures that any attempt to create EC2 instances without the CostCenter tag key is denied right from the start. This enforces the requirement at the organizational level. Tag Policy: By creating a tag policy that enforces the CostCenter tag values to be from a known list, you can ensure that only valid cost center values are used across all EC2 instances. Script Update: Updating the script to not only scan for tag keys and values but also to update noncompliant resources with a default approved tag value ensures compliance and mitigates the issue of arbitrary string values. Comprehensive Solution: This approach addresses both the presence of the CostCenter tag and the correctness of its value, providing a comprehensive solution to the problem.
Srikantha 👍 1 Selected: A
SCP to require the CostCenter tag key: Prevents users from launching EC2 instances without the required tag. Tag policy to validate values: AWS tag policies can enforce allowed values for tag keys like CostCenter, across all accounts in an OU. Script enhancement for compliance: Script detects noncompliant resources and applies a default value, maintaining tag integrity and reducing manual intervention.
Changwha 👍 3 Selected: A
The answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The problem has three distinct facets and the solution must address each. First, some teams omit the CostCenter tag key entirely, so an SCP that prevents the creation of EC2 instances without the CostCenter tag key closes that gap at the point of creation, and f4b18ba noted this ensures any attempt to launch an instance without the tag is denied from the start, enforcing the requirement at the organizational level. Second, and most importantly for this scenario, developers supply arbitrary values for the tag, so an Organizations tag policy requiring the CostCenter tag to take values from a known list of cost centers is the control that actually validates the value; Srikantha observed that AWS tag policies can enforce allowed values for tag keys. Third, resources created before these controls existed still carry bad values, so the script is updated to scan both tag keys and tag values and to modify noncompliant resources with a default approved value, which corrects the estate rather than only reporting on it. Option A is the only choice containing all three, which is why f4b18ba selected it and why Srikantha's description of the SCP and tag policy roles matches it. A is the correct answer.

Why the Other Options Are Wrong

B creates an SCP preventing EC2 creation without the CostCenter tag key, attaches it to the OU, and updates the script to scan tag keys and values and notify administrators when values are invalid. This leaves the core problem untouched: the SCP only requires that the key be present, so a developer can continue to supply any arbitrary string, and notifying the account administrator neither corrects the instance nor prevents the workaround. Srikantha's description of the tag policy's role in validating values shows precisely what option B omits. C creates the same SCP and adds an IAM permissions boundary in the member accounts that restricts CostCenter tag values to a list of valid cost centers. A permissions boundary caps the API actions a principal is authorized to perform; it has no ability to constrain the value of a tag applied to a resource, so it cannot enforce a valid-value list and the arbitrary-value workaround remains available. D creates a tag policy requiring valid CostCenter values, attaches it to the OU, and configures a Lambda that adds an empty CostCenter tag key to an EC2 instance together with an EventBridge rule matching RunInstances. Adding an empty tag value satisfies neither the tag policy's requirement for a known value nor the need to correct instances that already carry arbitrary values, so this option gates only new RunInstances calls while leaving the existing noncompliant estate and the notification loop unresolved. A is correct.

Community Comment Notes

Community voted A unanimously. f4b18ba explained the role of the SCP, that it denies any attempt to create EC2 instances without the CostCenter tag key from the start, enforcing the requirement at the organizational level, and Srikantha described the complementary tag policy that validates values against a known list of cost centers. Changwha confirmed A. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide