A SysOps Administrator must devise a strategy for enforcing tagging of all EC2 instances and Amazon Elastic Block Store (Amazon EBS) volumes. What action can the Administrator take to implement this for real-time enforcement?
A.
Use the AWS Tag Editor to manually search for untagged resources and then tag them properly in the editor.
B.
Set up AWS Service Catalog with the TagOptions Library rule that enforces a tagging taxonomy proactively when instances and volumes are launched.
C.
In a PowerShell or shell script, check for untagged items by using the resource tagging GetResources API action, and then manually tag the reported items.
D.
Launch items by using the AWS API. Use the TagResources API action to apply the required tags when the instances and volumes are launched.
shoule be B.
(Reactive governance is used to identify improper tags, programmatically using tools such as the Resource Groups Tagging API, AWS Config Rules, and custom scripts, or manually using Tag Editor and detailed billing reports. Proactive governance leverages tools such as AWS CloudFormation, AWS Service Catalog, or IAM resource-level permissions to ensure standardized tags are consistently applied at resource creation. For example, you can use the AWS CloudFormation Resource Tags property to apply tags to certain resource types. In AWS Service Catalog, you can add portfolio and product tags that are combined and applied to a provisioned product automatically when it is launched.)
Option B is correct because AWS Service Catalog allows administrators to create and manage catalogs of IT services that are approved for use on AWS. With the TagOptions Library, you can enforce a tagging taxonomy proactively when instances and volumes are launched. This ensures that all resources are tagged at the time of creation, providing real-time enforcement of the tagging strategy.
Option D is a more direct and efficient approach as it allows the Administrator to enforce tagging at the time of resource creation by using the TagResources API action. This ensures that tags are applied immediately and consistently without requiring manual intervention or additional configurations.
While options A and B can be used for remediation or enforcing tagging in existing resources, option D is specifically focused on real-time enforcement during resource creation.
Answer is "B".
In an organization, we can create default templates for all resources (in the Service Catalog) we can use and can add tagging, logging and other prerequisites well in advance; so any new resource consumed in the organization will have the standard defined by the company.
B. Set up AWS Service Catalog with the TagOptions Library rule that enforces a tagging taxonomy proactively when instances and volumes are launched.
will be the right answer.
AWS Service Catalog allows organizations to create and manage catalogs of IT services that are
approved for use on AWS. These IT services can include everything from virtual machine
images, servers, software, and databases to complete multi-tier application environments. AWS
Service Catalog enables a self-service capability for users, allowing them to provision the
services they need while also helping you to maintain consistent governance – including the
application of required tags and tag values.
ANS is B
Should be B
After a TagOption is created, you can associate it to a resource from the detail page of that product or portfolio.
If multiple TagOptions with the same key and different values are applied to a resource, a user launching that resource sees a list of value options to choose from. Upon launch, the set of administrator-associated and user-selected TagOptions are added as tags to the product.
The question mention real-time, and "manually" updating tags cannot be considered as real-time. Using the service catalog will do it , so B is the answer, though this will only apply to resources provisioned through the service catalog.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dkp
Highly Voted 3 years, 1 month agokarmaah
3 years agosaumenP
Highly Voted 3 years, 1 month agoe45af42
Most Recent 4 months, 4 weeks agoalbert_kuo
1 year, 3 months agoantthomas
2 years, 9 months agoHuy
2 years, 11 months agoHVarada
2 years, 11 months agoabhishek_m_86
2 years, 11 months agoChirantan
2 years, 11 months agoRadhaghosh
2 years, 11 months agojackdryan
3 years agoMFDOOM
3 years agojpush
3 years agoSONLE
3 years agorathimonika
3 years agoTheKsi
3 years agoa_w_s
3 years ago