nerdexam
AmazonAmazon

DOP-C02 · Question #30

DOP-C02 Question #30: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #30. The question stem and answer options stay visible for context.

Submitted by satoshi_tk· Mar 6, 2026Security & Compliance

Question

A DevOps engineer needs to apply a core set of security controls to an existing set of AWS accounts. The accounts are in an organization in AWS Organizations. Individual teams will administer individual accounts by using the AdministratorAccess AWS managed policy. For all accounts. AWS CloudTrail and AWS Config must be turned on in all available AWS Regions. Individual account administrators must not be able to edit or delete any of the baseline resources. However, individual account administrators must be able to edit or delete their own CloudTrail trails and AWS Config rules. Which solution will meet these requirements in the MOST operationally efficient way?

Options

  • ACreate an AWS CloudFormation template that defines the standard account resources. Deploy
  • BEnable AWS Control Tower. Enroll the existing accounts in AWS Control Tower. Grant the
  • CDesignate an AWS Config management account. Create AWS Config recorders in all accounts by
  • DCreate an AWS CloudFormation template that defines the standard account resources. Deploy

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Organizations#SCP#CloudTrail Organization Trail#AWS Config
Full DOP-C02 PracticeBrowse All DOP-C02 Questions