nerdexam
AmazonAmazon

DOP-C02 · Question #153

DOP-C02 Question #153: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #153. The question stem and answer options stay visible for context.

Submitted by suresh_in· Mar 6, 2026Security & Compliance

Question

A company uses AWS Secrets Manager to store a set of sensitive API keys that an AWS Lambda function uses. When the Lambda function is invoked the Lambda function retrieves the API keys and makes an API call to an external service. The Secrets Manager secret is encrypted with the default AWS Key Management Service (AWS KMS) key. A DevOps engineer needs to update the infrastructure to ensure that only the Lambda function's execution role can access the values in Secrets Manager. The solution must apply the principle of least privilege. Which combination of steps will meet these requirements? (Choose two.)

Options

  • AUpdate the default KMS key for Secrets Manager to allow only the Lambda function's execution
  • BCreate a KMS customer managed key that trusts Secrets Manager and allows the Lambda
  • CCreate a KMS customer managed key that trusts Secrets Manager and allows the account's root
  • DEnsure that the Lambda function's execution role has the KMS permissions scoped on the
  • ERemove all KMS permissions from the Lambda function's execution role

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Secrets Manager#AWS KMS#IAM Roles#Least Privilege
Full DOP-C02 PracticeBrowse All DOP-C02 Questions