The company uses AWS Organizations to manage multiple accounts. Every EC2 instance must include a BusinessUnit tag for cost allocation. An audit found some instances missing the tag and the company manually added them. How should a solutions architect enforce the BusinessUnit tag going forward?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Service Control Policy (SCP) and attach it to the organization root. The SCP should include a statement that enforces the presence of the BusinessUnit tag on EC2 instances..
Why this is the answer
The correct answer is to create a Service Control Policy (SCP) and attach it to the organization root. SCPs are powerful tools within AWS Organizations that allow you to enforce maximum permissions for all accounts in your organization. By creating an SCP that explicitly denies the creation or modification of EC2 instances if the BusinessUnit tag is missing, you can effectively enforce this tagging requirement across all accounts. Attaching it to the organization root ensures it applies to all OUs and accounts. Tag policies are primarily for reporting and identifying non-compliant resources, not for preventing resource creation. While they can report on missing tags, they do not block actions. Attaching an SCP to only the management account would not enforce the policy on member accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed