DOP-C02 · Question #175
DOP-C02 Question #175: Real Exam Question with Answer & Explanation
Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #175. The question stem and answer options stay visible for context.
Question
A company has an AWS Control Tower landing zone. The company's DevOps team creates a workload OU. A development OU and a production OU are nested under the workload OU. The company grants users full access to the company's AWS accounts to deploy applications. The DevOps team needs to allow only a specific management IAM role to manage the IAM roles and policies of any AWS accounts in only the production OU. Which combination of steps will meet these requirements? (Choose two.)
Options
- ACreate an SCP that denies full access with a condition to exclude the management IAM role for
- BEnsure that the FullAWSAccess SCP is applied at the organization root.
- CCreate an SCP that allows IAM related actions. Attach the SCP to the development OU.
- DCreate an SCP that denies IAM related actions with a condition to exclude the management IAM
- ECreate an SCP that denies IAM related actions with a condition to exclude the management IAM
Unlock DOP-C02 to see the answer
You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.