nerdexam
AmazonAmazon

DOP-C02 · Question #240

DOP-C02 Question #240: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #240. The question stem and answer options stay visible for context.

Submitted by omar99· Mar 6, 2026Security & Compliance

Question

A company wants to deploy a workload on several hundred Amazon EC2 instances. The company will provision the EC2 instances in an Auto Scaling group by using a launch template. The workload will pull files from an Amazon S3 bucket, process the data, and put the results into a different S3 bucket. The EC2 instances must have least-privilege permissions and must use temporary security credentials. Which combination of steps will meet these requirements? (Choose two.)

Options

  • ACreate an IAM role that has the appropriate permissions for S3 buckets Add the IAM role to an
  • BUpdate the launch template to include the IAM instance profile.
  • CCreate an IAM user that has the appropriate permissions for Amazon S3 Generate a secret key
  • DCreate a trust anchor and profile Attach the IAM role to the profile.
  • EUpdate the launch template Modify the user data to use the new secret key and token.

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM Roles#EC2 Security#Least Privilege#Launch Templates
Full DOP-C02 PracticeBrowse All DOP-C02 Questions