nerdexam
AmazonAmazon

DOP-C02 · Question #434

DOP-C02 Question #434: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #434. The question stem and answer options stay visible for context.

Submitted by chen.hong· Mar 6, 2026Security and Compliance

Question

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company has enabled all features for the organization. The member accounts under one OU contain S3 buckets that store sensitive data. A DevOps engineer wants to ensure that only IAM principals from within the organization can access the S3 buckets in the OU. Which solution will meet this requirement?

Options

  • ACreate an SCP in the management account of the organization to restrict Amazon S3 actions by
  • BCreate an IAM permissions boundary in the management account of the organization to restrict
  • CConfigure AWS Resource Access Manager (AWS RAM) to restrict access to S3 buckets in the
  • DCreate a resource control policy (RCP) in the management account of the organization to restrict

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Organizations SCP#Amazon S3 security#Data access control#IAM principals
Full DOP-C02 PracticeBrowse All DOP-C02 Questions