exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 918 discussion

Exam question from Amazon's AWS-SysOps
Question #: 918
Topic #: 1
[All AWS-SysOps Questions]

A company's AWS account users are launching Amazon EC2 instances without required cost allocation tags. A SysOps administrator needs to prevent users within an organization in AWS Organizations from launching new EC2 instances that do not have the required tags. The solution must require the least possible operational overhead.
Which solution meets these requirements?

  • A. Set up an AWS Lambda function that will initiate a run instance event and check for the required tags. Configure the function to prevent the launch of EC2 instances if the tags are missing.
  • B. Set up an AWS Config rule to monitor for EC2 instances that lack the required tags.
  • C. Set up a service control policy (SCP) that prevents the launch of EC2 instances that lack the required tags. Attach the SCP to the organization root.
  • D. Set up an Amazon CloudWatch alarm to stop any EC2 instances that lack the required tags.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
albert_kuo
9 months, 2 weeks ago
Selected Answer: C
Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to set permissions across all accounts in your organization. By creating an SCP and attaching it to the organization root, you can control what actions are allowed or denied for all accounts within the organization. In this case, you can create an SCP that denies the ability to launch EC2 instances if they do not have the required cost allocation tags.
upvoted 1 times
albert_kuo
8 months, 2 weeks ago
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_tagging.html
upvoted 1 times
...
...
ZL23
2 years, 6 months ago
C https://aws.amazon.com/blogs/aws-cost-management/cost-allocation-blog-series-3-enforce-and-validate-aws-resource-tags/
upvoted 3 times
...
Huy
2 years, 6 months ago
AWS Config is for compliance checking, it can't enforce the use of tags. SCP can be used that means C.
upvoted 4 times
...
ahaffar
2 years, 6 months ago
the question didnt mention that they are using AWS organization.
upvoted 1 times
ahaffar
2 years, 6 months ago
sorry there is AWS org.
upvoted 1 times
...
...
haim96
2 years, 6 months ago
B. Set up an AWS Config rule to monitor for EC2 instances that lack the required tags. https://aws.amazon.com/blogs/devops/aws-config-checking-for-compliance-with-new-managed-rule-options/
upvoted 3 times
...
qurren
2 years, 7 months ago
Answer is C. SCP is always way to go
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago