AWS Certified Solutions Architect – Associate (SAA-C03)Design Cost-Optimized ArchitecturesHard

A global company uses AWS Organizations to manage multiple AWS accounts. They have several development teams that frequently spin up and tear down EC2 instances, sometimes leaving them running unnecessarily overnight or on weekends. The company wants to implement a cost-optimization strategy to automatically identify and stop/terminate idle EC2 instances across all accounts. Which AWS service or feature combination is the most cost-effective and scalable for this task?

  1. AUse AWS Budgets to notify teams when costs exceed thresholds, relying on manual remediation.
  2. BDevelop custom Lambda functions triggered by CloudWatch events to check instance activity and stop them.
  3. CImplement AWS Config rules combined with Systems Manager Automation documents to identify and remediate non-compliant (idle) instances.
  4. DManually review and stop instances using the AWS Management Console.
Show answer & explanation

Correct answer: C. Implement AWS Config rules combined with Systems Manager Automation documents to identify and remediate non-compliant (idle) instances.

AWS Config can continuously monitor resource configurations and detect non-compliant resources (e.g., EC2 instances running outside tagged hours or with low CPU). Combined with AWS Systems Manager Automation documents, it can automatically remediate these non-compliant resources by stopping or terminating them. This approach is scalable across multiple accounts in AWS Organizations and provides automated, cost-effective governance.

Why the other options are wrong

  • A. AWS Budgets provides notifications but relies on manual remediation, which is not automated or scalable enough for the described problem of 'frequently spin up and tear down' and 'automatically identify and stop/terminate'.
  • B. Custom Lambda functions could work, but AWS Config and Systems Manager provide a more integrated, managed, and scalable solution for compliance-driven automation without building and maintaining custom code for basic resource governance.
  • D. Manual review is not scalable or cost-effective for 'multiple AWS accounts' and 'frequently spin up and tear down' instances, leading to human error and missed opportunities.

AWS Config for Cost Governance

AWS Config provides a detailed view of the configuration of AWS resources in your account. You can use it to assess, audit, and evaluate the configurations of your AWS resources, including identifying non-compliant resources that might incur unnecessary costs.

  • Continuously monitors and records AWS resource configurations.
  • Evaluates configurations against desired settings (Config Rules).
  • Can trigger remediation actions via Systems Manager Automation.
  • Scalable across multiple accounts with AWS Organizations.

Memory trick: Config is the watchdog that tells Systems Manager (the dog walker) to put the idle dogs (instances) back in their kennels.

More Design Cost-Optimized Architectures questions