Several business units must provision EC2 instances, but the company requires that they use only approved, standardized instance configurations. What is the best way for the SysOps administrator to enforce that requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Publish an AWS Service Catalog product for EC2 with a launch constraint role and let business units provision only through Service Catalog..
Why this is the answer
Publishing an AWS Service Catalog product for EC2 with a launch constraint role is the best solution because Service Catalog is designed precisely for this use case. It allows administrators to create and manage a catalog of approved IT services, including EC2 instances, and enforce standardized configurations. The launch constraint role ensures that instances are provisioned with the specified parameters, regardless of the end-user's permissions. Business units can then provision instances through a self-service portal, adhering to company standards. Creating an EC2 launch configuration is insufficient because users can still launch instances outside of it. An IAM policy restricting provisioning would be overly complex to manage and wouldn't directly enforce specific configurations. Sharing a CloudFormation template is better, but it still relies on users correctly applying the template and doesn't offer the same level of centralized control and self-service as Service Catalog.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed