DOP-C02 exam dumps

DOP-C02 practice question 369 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 369

Single answer

Your organization uses AWS Organizations to manage multiple accounts. As a DevOps Engineer, you are tasked with ensuring that no account, including those belonging to development teams, can create or modify IAM roles to include the 'AdministratorAccess' policy. However, you also need to allow security teams to create or modify roles with this permission in a specific management account. How can you accomplish this using Service Control Policies (SCPs)?

  1. A

    Create an SCP that explicitly denies attaching the 'AdministratorAccess' policy to IAM roles, and attach it to the root of the organization.

  2. B

    Create an SCP that denies attaching the 'AdministratorAccess' policy unless the operation is performed in the management account, and attach it to the root of the organization.

  3. C

    Create an SCP that explicitly allows attaching the 'AdministratorAccess' policy to IAM roles for the management account, and attach it only to the management account's organizational unit (OU).

  4. D

    Create an SCP that denies all actions involving IAM roles across all accounts, and create an exception for the management account.

Show answer and explanation

Correct answer: B

Explanation

To enforce organizational governance while maintaining the security team's ability to operate, SCPs should be scoped appropriately. An SCP that denies attaching the 'AdministratorAccess' policy unless the operation is performed in the management account ensures that unauthorized accounts cannot misuse this powerful permission, while still enabling the security team to perform necessary tasks in their designated account. SCPs are evaluated at the organizational level, and explicit denies always take precedence over allows, making this approach the most effective solution.

  • A. Incorrect.

    This option would block all accounts from attaching the 'AdministratorAccess' policy, including the management account where the security team needs this ability. SCPs operate at the organizational level, and this approach does not fulfill the requirement to allow security teams specific access.

  • B. Correct.

    This is the correct option. By creating an SCP that denies attaching the 'AdministratorAccess' policy except in the management account, you can enforce the restriction globally while allowing the security team to perform their required actions in the designated account.

  • C. Incorrect.

    This option explicitly allows attaching the 'AdministratorAccess' policy in the management account but does not restrict its use in other accounts. SCPs are evaluated based on explicit denies taking precedence over allows, so this would not meet the requirements.

  • D. Incorrect.

    This option is overly restrictive and would block all IAM role actions across all accounts, which is not aligned with the requirement of only restricting the 'AdministratorAccess' policy.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam