nerdexam
AmazonAmazon

DOP-C02 · Question #306

DOP-C02 Question #306: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #306. The question stem and answer options stay visible for context.

Submitted by layla.eg· Mar 6, 2026Security and Compliance

Question

A company has multiple AWS accounts. The company uses AWS IAM Identity Center that is integrated with a third-party SAML 2.0 identity provider (IdP). The attributes for access control feature is enabled in IAM Identity Center. The attribute mapping list maps the department key from the IdP to the ${path:enterprise.department} attribute. All existing Amazon EC2 instances have a d1, d2, d3 department tag that corresponds to three company's departments. A DevOps engineer must create policies based on the matching attributes. The policies must grant each user access to only the EC2 instances that are tagged with the user's respective department name. Which condition key should the DevOps engineer include in the custom permissions policies to meet these requirements?

Options

  • AOption A
  • BOption B
  • COption C
  • DOption D

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Attribute-Based Access Control (ABAC)#IAM Identity Center (SSO)#IAM policies#Resource tagging
Full DOP-C02 PracticeBrowse All DOP-C02 Questions