DOP-C02 exam dumps

DOP-C02 practice question 364 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 364

Single answer

Your organization uses AWS Identity and Access Management (IAM) to manage permissions. As a DevOps engineer, you are tasked with creating a mechanism to delegate permission management to team leads for their respective teams, while ensuring they cannot grant permissions that exceed the organization's compliance policies. How can you achieve this using IAM permissions boundaries?

  1. A

    Create an IAM policy for each team lead that explicitly defines the permissions they can assign to their team members.

  2. B

    Assign an IAM permissions boundary to each team lead, restricting the maximum permissions they can delegate to their team members.

  3. C

    Use AWS Organizations Service Control Policies (SCPs) to set permissions for team leads to manage their team members' access.

  4. D

    Define a permissions boundary for the IAM roles created by team leads and attach that boundary to those roles.

Show answer and explanation

Correct answer: B

Explanation

IAM permissions boundaries provide a mechanism to delegate permission management while enforcing limits on what permissions can be granted. By assigning a permissions boundary to team leads, you can ensure they can only delegate permissions up to the limits defined in the boundary, thus adhering to compliance requirements. Other options either do not use permissions boundaries or misuse them.

  • A. Incorrect.

    This option is incorrect because assigning an explicit IAM policy to team leads only defines what the leads themselves can do, but does not restrict the permissions they can delegate to their team members.

  • B. Correct.

    This is correct. IAM permissions boundaries allow you to enforce a maximum permissions limit. By assigning a permissions boundary to team leads, you can ensure they cannot grant permissions that exceed the boundary.

  • C. Incorrect.

    This option is incorrect because SCPs are applied at the organization level and affect all users and roles in an account or organizational unit. SCPs do not provide granular control over delegation of permissions by specific team leads.

  • D. Incorrect.

    This option is incorrect because permissions boundaries are attached to IAM roles or users, not directly applied by team leads to the roles they create.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam