Use an SCP to require the CostCenter tag, a tag policy for valid values, and update the script to fix noncompliant resources
A company uses an organization in AWS Organizations to manage its 500 AWS accounts. The organization has all features enabled. The AWS accounts are in a single OU. The developers need to use the CostCenter tag key for all resources in the organization's member accounts. Some teams do not use the CostCenter tag key to tag their Amazon EC2 instances. The cloud team wrote a script that scans all EC2 instances in the organization's member accounts. If the EC2 instances do not have a CostCenter tag key, the script will notify AWS account administrators. To avoid this notification, some developers use the CostCenter tag key with an arbitrary string in the tag value. The cloud team needs to ensure that all EC2 instances in the organization use a CostCenter tag key with the appropriate cost center value. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Only option A addresses all three failure modes, which is why each element is needed (A). The SCP prevents the tag key from being missing entirely. The tag policy is the only control that can validate the tag's value against a known list, because neither an SCP nor an IAM permission boundary can restrict a string value the way a tag policy can. And updating the script to both inspect values and fix noncompliant resources closes the loop, since a resource created before the controls existed still has to be corrected. f4b18ba and Srikantha both identified the division of labour between the SCP and the tag policy.
Developers are tagging EC2 instances with arbitrary CostCenter values to silence the notification script, so the tag key is present but the value is meaningless. Three controls are needed together. An SCP prevents the creation of EC2 instances without the CostCenter tag key, enforcing the requirement at creation. An Organizations tag policy restricts the CostCenter tag to values from the known list of cost centers, so an arbitrary string is rejected. Finally, the existing script is updated to inspect both tag keys and tag values and to modify noncompliant resources with a default approved value rather than merely notifying administrators.
Attaching only the SCP that requires the CostCenter tag key and updating the script to notify administrators when tag values are invalid (B) — this does nothing about the arbitrary values: the SCP only requires the key to be present, so a developer can keep supplying any string and simply receive a notification, and notifying does not correct the resource. Adding an IAM permission boundary restricting CostCenter tag values (C in option C) — a permissions boundary caps which API actions a principal may call and cannot constrain the value of a tag on a resource, so it cannot enforce a valid-value list. Creating a tag policy plus a Lambda that adds an empty CostCenter tag and an EventBridge rule on RunInstances (D) — adding an empty tag value to a new instance does not validate against the list and does not remediate existing noncompliant instances, so the arbitrary-value workaround continues.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The problem has three distinct facets and the solution must address each. First, some teams omit the CostCenter tag key entirely, so an SCP that prevents the creation of EC2 instances without the CostCenter tag key closes that gap at the point of creation, and f4b18ba noted this ensures any attempt to launch an instance without the tag is denied from the start, enforcing the requirement at the organizational level. Second, and most importantly for this scenario, developers supply arbitrary values for the tag, so an Organizations tag policy requiring the CostCenter tag to take values from a known list of cost centers is the control that actually validates the value; Srikantha observed that AWS tag policies can enforce allowed values for tag keys. Third, resources created before these controls existed still carry bad values, so the script is updated to scan both tag keys and tag values and to modify noncompliant resources with a default approved value, which corrects the estate rather than only reporting on it. Option A is the only choice containing all three, which is why f4b18ba selected it and why Srikantha's description of the SCP and tag policy roles matches it. A is the correct answer.Why the Other Options Are Wrong
B creates an SCP preventing EC2 creation without the CostCenter tag key, attaches it to the OU, and updates the script to scan tag keys and values and notify administrators when values are invalid. This leaves the core problem untouched: the SCP only requires that the key be present, so a developer can continue to supply any arbitrary string, and notifying the account administrator neither corrects the instance nor prevents the workaround. Srikantha's description of the tag policy's role in validating values shows precisely what option B omits. C creates the same SCP and adds an IAM permissions boundary in the member accounts that restricts CostCenter tag values to a list of valid cost centers. A permissions boundary caps the API actions a principal is authorized to perform; it has no ability to constrain the value of a tag applied to a resource, so it cannot enforce a valid-value list and the arbitrary-value workaround remains available. D creates a tag policy requiring valid CostCenter values, attaches it to the OU, and configures a Lambda that adds an empty CostCenter tag key to an EC2 instance together with an EventBridge rule matching RunInstances. Adding an empty tag value satisfies neither the tag policy's requirement for a known value nor the need to correct instances that already carry arbitrary values, so this option gates only new RunInstances calls while leaving the existing noncompliant estate and the notification loop unresolved. A is correct.Community Comment Notes
Community voted A unanimously. f4b18ba explained the role of the SCP, that it denies any attempt to create EC2 instances without the CostCenter tag key from the start, enforcing the requirement at the organizational level, and Srikantha described the complementary tag policy that validates values against a known list of cost centers. Changwha confirmed A. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →