nerdexam
AmazonAmazon

DOP-C02 · Question #336

DOP-C02 Question #336: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #336. The question stem and answer options stay visible for context.

Submitted by khalil_dz· Mar 6, 2026Configuration Management & Infrastructure as Code

Question

A company has an organization in AWS Organizations with many Oils that contain many AWS accounts. The organization has a dedicated delegated administrator AWS account. The company needs the accounts in one OU to have server-side encryption enforced for all Amazon Elastic Block Store (Amazon EBS) volumes and Amazon Simple Queue Service (Amazon SQS) queues that are created or updated on an AWS CloudFormation stack. Which solution will enforce this policy before a CloudFormation stack operation in the accounts of this OU?

Options

  • AActivate trusted access to CloudFormation StackSets. Create a CloudFormation Hook that
  • BSet up AWS Config in all the accounts in the OU. Use AWS Systems Manager to deploy AWS
  • CWrite an SCP to deny the creation of EBS volumes and SQS queues unless the EBS volumes
  • DCreate an AWS Lambda function in the delegated administrator account that checks whether

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Organizations#CloudFormation Hooks#Policy Enforcement#Server-side Encryption
Full DOP-C02 PracticeBrowse All DOP-C02 Questions