nerdexam
Amazon

DOP-C02 · Question #344

A company is using AWS Organizations and wants to implement a governance strategy with the following requirements: - AWS resource access is restricted to the same two Regions for all accounts. - AWS s

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #344. The question stem and answer options stay visible for context.

Submitted by kavita_s· Mar 6, 2026Security & Compliance

Question

A company is using AWS Organizations and wants to implement a governance strategy with the following requirements:

  • AWS resource access is restricted to the same two Regions for all

accounts.

  • AWS services are limited to a specific group of authorized services

for all accounts.

  • Authentication is provided by Active Directory.
  • Access permissions are organized by job function and are identical in

each account. Which solution will meet these requirements?

Options

  • AEstablish an organizational unit (OU) with group policies in the management account to restrict
  • BEstablish a permission boundary in the management account to restrict Regions and authorized
  • CEstablish a service control policy in the management account to restrict Regions and authorized
  • DEstablish a service control policy in the management account to restrict Regions and authorized

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Organizations#Service Control Policies (SCPs)#AWS IAM Identity Center#Multi-account Governance
Full DOP-C02 Practice