DOP-C02 exam dumps

DOP-C02 practice question 349 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 349

Select 2

Your organization uses AWS Organizations to manage multiple AWS accounts. The security team has mandated that all accounts enforce least privilege access and centralize identity management. They also require that specific IAM policies be automatically applied to all accounts in the organization to restrict certain actions. Which approach should you implement to meet these requirements?

  1. A

    Use AWS Organizations Service Control Policies (SCPs) to define permissions at the organization or organizational unit (OU) level.

  2. B

    Set up AWS Single Sign-On (SSO) to manage user access across all accounts from a centralized location.

  3. C

    Create IAM roles in all member accounts, and configure AWS Lambda to apply least privilege policies to these roles periodically.

  4. D

    Enable cross-account IAM role trust relationships between all member accounts and the management account.

  5. E

    Use AWS Config rules to ensure compliance with specific IAM policies across all accounts.

Show answer and explanation

Correct answers: A, B

Explanation

To implement identity and access management at scale, AWS Organizations Service Control Policies (SCPs) provide a scalable way to enforce least privilege access across multiple AWS accounts. AWS Single Sign-On (SSO) allows centralized identity management, simplifying user and group permission management across accounts. Together, these tools meet the requirements for centralized management and enforcement of least privilege access, making them the best options for this scenario.

  • A. Correct.

    Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to define permission guardrails for all accounts in an organization or within an organizational unit (OU). It is the most scalable way to enforce least privilege access across multiple accounts.

  • B. Correct.

    AWS Single Sign-On (SSO) is a service that allows you to manage user identities and permissions for multiple AWS accounts from a centralized location. It simplifies identity and access management at scale.

  • C. Incorrect.

    While you can use IAM roles with Lambda to manage permissions, this approach is operationally complex and does not scale well for large organizations. It is not the most efficient method for enforcing least privilege access at scale.

  • D. Incorrect.

    Cross-account IAM role trust relationships are useful for specific use cases but do not address the requirement for centralized identity management or enforcement of least privilege access across all accounts.

  • E. Incorrect.

    AWS Config rules can help monitor compliance for IAM policies but cannot directly enforce least privilege access or centralize identity management. Config rules are more suited for auditing and compliance purposes rather than direct enforcement.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam