DOP-C02 · Question #73
DOP-C02 Question #73: Real Exam Question with Answer & Explanation
Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #73. The question stem and answer options stay visible for context.
Question
An ecommerce company has chosen AWS to host its new platform. The company's DevOps team has started building an AWS Control Tower landing zone. The DevOps team has set the identity store within AWS IAM Identity Center (AWS Single Sign-On) to external identity provider (IdP) and has configured SAML 2.0. The DevOps team wants a robust permission model that applies the principle of least privilege. The model must allow the team to build and manage only the team's own resources. Which combination of steps will meet these requirements? (Choose three.)
Options
- ACreate IAM policies that include the required permissions. Include the aws:PrincipalTag condition
- BCreate permission sets. Attach an inline policy that includes the required permissions and uses
- CCreate a group in the IdP. Place users in the group. Assign the group to accounts and the
- DCreate a group in the IdP. Place users in the group. Assign the group to OUs and IAM policies.
- EEnable attributes for access control in IAM Identity Center. Apply tags to users. Map the tags as
- FEnable attributes for access control in IAM Identity Center. Map attributes from the IdP as key-
Unlock DOP-C02 to see the answer
You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.