A company is operating a new workload across accounts in an AWS Organizations organization. Every running resource must have a CostCenter tag, and that tag must contain one of three approved values. The company must enforce this policy and prevent any CostCenter tag changes to a value that is not approved.
Which solution meets these requirements?
A Create an AWS Config Custom Policy rule by using AWS CloudFormatlon Guard. Include the tag key of CostCenter and the approved values. Create an SCP that denies the creation of resources when the value of the aws:RequestTagCostCenter condition key is not one of the three approved values. B Create an AWS CloudTrail trail. Create an Amazon EventBridge rule that includes a rule statement that matches the creation of new resources. Configure the EventBridge rule to invoke an AWS Lambda function that checks for the CostCenter tag. Program the Lambda function to block creation in case of a noncompliant value. C Enable tag policies for the organization. Create a tag policy that specifies a tag key of CostCenter and the approved values. Configure the policy to enforce noncompliant operations. Create an SCP that denies the creation of resources when the aws:RequestTag.CostCenter condition key has a null value. D Enable tag policies for the organization. Create a tag policy that specifies a tag key of CostCenter and the approved values. Create an Amazon EventBridge rule that invokes an AWS Lambda function when a noncompliant tag is created. Program the Lambda function to block changes to the tag. Show Answer Answer Explanation AWS Organizations tag policies can specify the permitted values for the CostCenter tag and enforce noncompliant tagging operations, preventing requests that set the tag to an unapproved value. Because tag-policy value enforcement does not require a tag to be supplied at resource creation, an SCP using a Null condition on aws:RequestTag/CostCenter is needed to deny creation requests that omit the required tag.
Learn more
Community Discussion