Use AWS Service Catalog with CloudFormation and enforce tagging with AWS Config rules

Implement a secure and consistent deployment strategy for cloud resources. Develop a strategy to centrally deploy and manage AWS accounts.
Answer Correct answer: D — use Service Catalog with CloudFormation for approved patterns and AWS Config rules to enforce tagging.

A company needs to securely deploy resources and workloads across AWS accounts. The accounts are in an organization in AWS Organizations. The company needs to use AWS CloudFormation for infrastructure as code (IaC) management of approved architectural patterns. The company also must enforce tagging requirements and specific guidelines for resource and workload configuration and creation. Which solution will meet these requirements?

  1. Use CloudFormation stack policies to prevent the creation of resources that do not meet the tagging or configuration requirements. Use Amazon EventBridge rules to detect API calls that attempt to create resources outside of CloudFormation.
  2. Use an AWS CodePipeline pipeline to test and deploy IaC defined workloads through CloudFormation into the accounts. Use AWS Config rules to enforce the tagging requirements. Apply an SCP to prevent the creation of misconfigured resources in all OUs.
  3. Create an IAM permissions boundary to prevent the creation of misconfigured resources through CloudFormation and to enforce the tagging requirements. Apply the permissions boundary to all account roles. Use AWS Config rules to identify existing resources that are in a misconfigured state.
  4. Use AWS Service Catalog with CloudFormation to manage access to approved architecture configurations. Provision Service Catalog portfolios to the accounts across the organization. Use AWS Config rules to enforce the tagging requirements and other resource configuration policies across accounts. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Service Catalog (D) is purpose-built to gate deployments to approved, versioned CloudFormation products and distribute them via portfolios across an organization—directly meeting 'approved architectural patterns' and 'specific configuration guidelines.' Config rules enforce tagging org-wide. Stack policies (A) only protect a single stack; CodePipeline (B) deploys but does not gate to approved patterns like a catalog; permissions boundaries (C) constrain roles but are not the approval-distribution mechanism. D is correct.

To deploy approved architectural patterns via CloudFormation across org accounts while enforcing tagging and configuration guidelines, use AWS Service Catalog: define approved CloudFormation templates as products in portfolios and provision those portfolios to the organization's accounts, so only vetted patterns can be launched. AWS Config rules then continuously enforce the tagging and configuration requirements across accounts.

Using stack policies (A)—they protect an individual stack from changes but do not distribute approved patterns across accounts. Using CodePipeline (B)—it tests and deploys IaC but does not restrict users to approved architectural patterns the way Service Catalog does. Permissions boundaries (C)—they limit role permissions, not the approved-pattern catalog. D is the fit.

Community Discussion (3 comments)

molerowan 👍 1 Selected: D
AWS Service Catalog with CloudFormation: Approved Architectural Patterns: Define standardized CloudFormation templates (products) in Service Catalog, ensuring all deployments adhere to approved configurations and tagging requirements. Centralized Governance: Distribute portfolios to accounts in the organization, restricting users to pre-approved IaC templates. AWS Config for Compliance Enforcement: Tagging and Configuration Rules: Use AWS Config managed/custom rules (e.g., required-tags, cloudformation-stack-drift) to detect and remediate non-compliant resources. Cross-Account Visibility: Aggregate findings in a delegated administrator account for centralized monitoring.
Bachhu 👍 1 Selected: D
It’s D. As it is applicable for AWS region.
Pmktechno 👍 1 Selected: D
AWS Service Catalog: This service allows you to create and manage catalogs of approved products that can be deployed using CloudFormation. This ensures that only approved architectural patterns are used. Provisioning Portfolios: By provisioning Service Catalog portfolios to the accounts across the organization, you can control which resources and configurations are available for deployment. AWS Config Rules: These rules can be used to enforce tagging requirements and other configuration policies, ensuring compliance across all accounts. This approach provides a comprehensive solution for managing and enforcing infrastructure standards and compliance across multiple AWS accounts.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Service Catalog lets you publish approved CloudFormation templates as products in portfolios and provision those portfolios to the organization's accounts, so teams can only launch vetted, compliant architectural patterns. AWS Config rules then enforce tagging and resource-configuration requirements across all accounts, satisfying both the approved-pattern and governance mandates.

Why the Other Options Are Wrong

A uses stack policies, which protect a single stack from modification but do not distribute approved patterns across accounts. B uses CodePipeline, which automates deployment but does not constrain teams to an approved catalog. C uses permissions boundaries, which limit a role's max permissions but are not the approved-pattern distribution mechanism. D is correct.

Community Comment Notes

Community voted D (100). Commenters described Service Catalog as the way to manage approved CloudFormation products and provision portfolios across the organization, with Config rules enforcing tagging. D confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide