DOP-C02 exam dumps

DOP-C02 practice question 365 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 365

Select 3

Your organization wants to allow a junior DevOps engineer to create IAM roles for EC2 instances, but the organization wants to restrict the permissions that the roles can grant to the EC2 instances. You are tasked with designing a solution using IAM permission boundaries to achieve this. Which combination of steps should you take to meet the requirements?

  1. A

    Create an IAM permissions boundary policy defining the maximum permissions that the roles created by the junior engineer can grant.

  2. B

    Attach the IAM permissions boundary policy to the junior engineer's IAM user or group.

  3. C

    Attach the IAM permissions boundary policy to the IAM roles created by the junior engineer.

  4. D

    Grant the junior engineer an IAM policy that allows them to create IAM roles and attach policies to those roles.

  5. E

    Grant the junior engineer full administrative access to create and manage any IAM resources.

Show answer and explanation

Correct answers: A, C, D

Explanation

To delegate permission management while maintaining control, you need to use IAM permissions boundaries. A permissions boundary policy defines the maximum permissions the roles can grant. This boundary is attached to the roles created by the junior engineer. Additionally, the junior engineer must have an IAM policy allowing them to create and manage roles. Granting full administrative access is unnecessary and goes against security best practices.

  • A. Correct.

    Correct: An IAM permissions boundary policy is required to restrict the maximum permissions that the roles created by the junior engineer can grant.

  • B. Incorrect.

    Incorrect: Permissions boundaries cannot be directly attached to an IAM user or group. They are attached to roles.

  • C. Correct.

    Correct: Permissions boundaries must be attached to the IAM roles created by the junior engineer to enforce the defined restrictions.

  • D. Correct.

    Correct: The junior engineer needs an IAM policy allowing them to create IAM roles and attach policies. Without this, they cannot create or manage roles.

  • E. Incorrect.

    Incorrect: Granting full administrative access violates the principle of least privilege and does not align with the requirement to restrict permissions.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam