nerdexam
Amazon

DOP-C02 · Question #467

A company wants governance where only specific Regions and services can be used, with centralized AD authentication and job-function-based roles. Which solution meets these requirements?

The correct answer is D. Use SCPs to restrict Regions/services and StackSets for IAM roles with trust to AD.. Apply SCPs for Region and service restriction. Use CloudFormation StackSets to consistently deploy IAM roles with trust policies for SSO/AD integration. This model enforces governance uniformly across all accounts per AWS multi-account best practices.

Submitted by yuki_2020· Mar 6, 2026Security and Compliance

Question

A company wants governance where only specific Regions and services can be used, with centralized AD authentication and job-function-based roles. Which solution meets these requirements?

Options

  • AUse OUs with group policies and StackSets for IAM roles.
  • BUse permission boundaries and StackSets.
  • CUse SCPs to restrict Regions/services and Resource Access Manager to share roles.
  • DUse SCPs to restrict Regions/services and StackSets for IAM roles with trust to AD.

How the community answered

(60 responses)
  • A
    17% (10)
  • B
    3% (2)
  • C
    7% (4)
  • D
    73% (44)

Explanation

Apply SCPs for Region and service restriction. Use CloudFormation StackSets to consistently deploy IAM roles with trust policies for SSO/AD integration. This model enforces governance uniformly across all accounts per AWS multi-account best practices.

Topics

#AWS Organizations#SCPs#IAM#Multi-account Governance

Community Discussion

No community discussion yet for this question.

Full DOP-C02 Practice