
AWSCertified DevOps Engineer - Professional
Domain 6Objective 1
Task Statement 6.1: Implement Techniques for Identity and Access Management at Scale. DOP-C02 Practice Questions (Page 1)
Part of the Content Domain 6: Security and Compliance domain, which accounts for 17% of the DOP-C02 exam. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 12–20 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
17%of the exam
Questions 1–5
- 1
When a user assumes a role and passes a session policy, what is the effective permission for the session?
Select an answer first - 2
A company has a fleet of EC2 instances that need to access AWS services. The instances are managed by an automated deployment system. The security team wants to ensure that the instances cannot use long-term access keys. What is the most effective way to achieve this?
Select an answer first - 3
What is the purpose of an IAM permissions boundary?
Select an answer first - 4
A company has an application that uses a database username and password stored in a configuration file. The security team wants to automate the rotation of these credentials without changing the application code. What should they use?
Select an answer first - 5
A company uses AWS Organizations with a management account and several member accounts. They want to allow developers in member accounts to create IAM roles, but they want to ensure that no role can access the management account's resources. What is the most effective way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DOP-C02” is a trademark of its owner, used for identification only.