nerdexam
AmazonAmazon

DOP-C02 · Question #260

DOP-C02 Question #260: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #260. The question stem and answer options stay visible for context.

Submitted by joshua94· Mar 6, 2026Security and Compliance

Question

A company deploys an application on on-premises devices in the company's on-premises data center. The company uses an AWS Direct Connect connection between the data center and the company's AWS account. During initial setup of the on-premises devices and during application updates, the application needs to retrieve configuration files from an Amazon Elastic File System (Amazon EFS) file system. All traffic from the on-premises devices to Amazon EFS must remain private and encrypted. The on-premises devices must follow the principle of least privilege for AWS access. The company's DevOps team needs the ability to revoke access from a single device without affecting the access of the other devices. Which combination of steps will meet these requirements? (Choose two.)

Options

  • ACreate an IAM user that has an access key and a secret key for each device. Attach the
  • BGenerate certificates for each on-premises device in AWS Private Certificate Authority. Create a
  • CCreate an IAM user that has an access key and a secret key for all devices. Attach the
  • DUse the amazon-efs-utils package to mount the EFS file system.
  • EUse the native Linux NFS client to mount the EFS file system.

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Hybrid connectivity#EFS on-premises access#PrivateLink for EFS#Certificate authentication
Full DOP-C02 PracticeBrowse All DOP-C02 Questions