nerdexam
AmazonAmazon

DOP-C02 · Question #497

DOP-C02 Question #497: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #497. The question stem and answer options stay visible for context.

Submitted by mike_84· Mar 6, 2026Security and Compliance

Question

A company wants to improve its security practices by enforcing least privilege across all projects. Developers must be able to access Amazon EC2 resources but not Amazon RDS resources. Database administrators must have access only to Amazon RDS resources. Every employee has a unique IAM user. There are already pre-existing IAM policies for developer and database administrator job functions. All AWS resources are already tagged with appropriate project tags. All the IAM users are tagged with the appropriate project and job function. The company must ensure that each employee can access only the project that the employee is working on. Which solution will meet these requirements? (Choose three.)

Options

  • AFor each project, create one IAM role for developers and one IAM role for database
  • BModify the pre-existing IAM policies to include a StringEquals ResourceTag condition for projects
  • CCreate an IAM policy that allows users to assume a role when the ResourceTag value matches
  • DCreate an IAM policy that allows users to assume a role when the ResourceTag value matches
  • ETag the pre-existing IAM policies with the appropriate projects and job functions. Attach the
  • FFor each project, create one IAM group for developers and one IAM group for database

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IAM policies#Least privilege#Resource tagging#Cross-account access
Full DOP-C02 PracticeBrowse All DOP-C02 Questions