exam questions

Exam AWS Certified DevOps Engineer - Professional DOP-C02 All Questions

View all questions & answers for the AWS Certified DevOps Engineer - Professional DOP-C02 exam

Exam AWS Certified DevOps Engineer - Professional DOP-C02 topic 1 question 160 discussion

A company has an AWS Control Tower landing zone. The company's DevOps team creates a workload OU. A development OU and a production OU are nested under the workload OU. The company grants users full access to the company's AWS accounts to deploy applications.

The DevOps team needs to allow only a specific management IAM role to manage the IAM roles and policies of any AWS accounts in only the production OU.

Which combination of steps will meet these requirements? (Choose two.)

  • A. Create an SCP that denies full access with a condition to exclude the management IAM role for the organization root.
  • B. Ensure that the FullAWSAccess SCP is applied at the organization root.
  • C. Create an SCP that allows IAM related actions. Attach the SCP to the development OU.
  • D. Create an SCP that denies IAM related actions with a condition to exclude the management IAM role. Attach the SCP to the workload OU.
  • E. Create an SCP that denies IAM related actions with a condition to exclude the management IAM role. Attach the SCP to the production OU.
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d262e67
Highly Voted 1 year, 3 months ago
Selected Answer: BE
You need to understand how SCP inheritance works in AWS. The way it works for Deny policies is different that allow policies. Allow polices are passing down to children ONLY if they don't have an allow policy. Deny policies always pass down to children. That's why there is always an SCP set to the Root to allow everything by default. If you limit this policy, the whole organization will be limited, not matter what other policies are saying for the other OUs. So it's not A. It's not D because it restricts the wrong OU.
upvoted 11 times
...
MalonJay
Most Recent 11 months, 3 weeks ago
CE FullAWSAccess is applied be default, no need to check it since the question did not say it has been removed. For an Action to be permitted it has to be allowed from the Root OUs all the way to the accounts.
upvoted 1 times
tinyshare
5 months ago
The organization root is NOT the top level OU. The question specifies the workload OU has full access, but not the organization root. So you still need B.
upvoted 1 times
...
...
dkp
1 year ago
Selected Answer: BE
ANS: B&E
upvoted 2 times
...
DanShone
1 year, 1 month ago
Selected Answer: BE
B & E are correct
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: BE
B-E, no debate
upvoted 3 times
...
Ramdi1
1 year, 2 months ago
Selected Answer: BE
B and E are correct because he requirement for dev ou user should still be able to do what they need to
upvoted 3 times
...
thanhnv142
1 year, 2 months ago
Selected Answer: BE
B and E are correct: A: this does not make sense. It would mess with permissions for all OUs C: The question requires <only the production OU>: we need to target the production OU, not development OU D: <Attach the SCP to the workload OU>: we need to target only the production OU. This option affects both dev and prod OUS
upvoted 3 times
...
denccc
1 year, 3 months ago
B & E it is
upvoted 1 times
...
a54b16f
1 year, 3 months ago
Selected Answer: BE
A is wrong, we only want to limit production OU, development OU users should be able to do anything
upvoted 2 times
...
kabary
1 year, 3 months ago
Selected Answer: BE
Answer is B & E. A is not correct because it would prevent the developers team to access the Developer OU. That wouldn't make sense.
upvoted 2 times
...
PrasannaBalaji
1 year, 3 months ago
Selected Answer: AE
A and E
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago