nerdexam
AmazonAmazon

DOP-C02 · Question #175

DOP-C02 Question #175: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #175. The question stem and answer options stay visible for context.

Submitted by femi9· Mar 6, 2026Security & Compliance

Question

A company has an AWS Control Tower landing zone. The company's DevOps team creates a workload OU. A development OU and a production OU are nested under the workload OU. The company grants users full access to the company's AWS accounts to deploy applications. The DevOps team needs to allow only a specific management IAM role to manage the IAM roles and policies of any AWS accounts in only the production OU. Which combination of steps will meet these requirements? (Choose two.)

Options

  • ACreate an SCP that denies full access with a condition to exclude the management IAM role for
  • BEnsure that the FullAWSAccess SCP is applied at the organization root.
  • CCreate an SCP that allows IAM related actions. Attach the SCP to the development OU.
  • DCreate an SCP that denies IAM related actions with a condition to exclude the management IAM
  • ECreate an SCP that denies IAM related actions with a condition to exclude the management IAM

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Organizations#Service Control Policies (SCPs)#IAM Access Management#Control Tower
Full DOP-C02 PracticeBrowse All DOP-C02 Questions