The company wants to enforce standardized tags with specific values when users create resources across the AWS Organization. Each organizational unit (OU) requires distinct tag values. What approach will enforce these tagging requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use a Service Control Policy (SCP) to deny resource creation when required tags are missing. Create a tag policy that defines the tag values assigned to each OU. Attach the tag policy to the OUs..
Why this is the answer
The correct approach combines an SCP and Tag Policies. An SCP effectively denies resource creation if required tags are missing, enforcing the presence of tags. Tag Policies, part of AWS Organizations, define specific tag keys and their allowed values. By attaching these Tag Policies to individual OUs, you can enforce distinct tag values for each OU, meeting the requirement for different values per OU. Incorrect options: Attaching the tag policy to the management account would apply the same tag values across all OUs, not allowing for distinct values per OU. An SCP that allows resource creation only when tags are present is less direct and harder to manage than a deny-based SCP for missing tags. Defining required tags only within an SCP doesn't allow for specifying or enforcing values for those tags, which is a key requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed