
AWSCertified DevOps Engineer - Professional
Domain 6Objective 1
Task Statement 6.1: Implement Techniques for Identity and Access Management at Scale. DOP-C02 Practice Questions (Page 3)
Part of the Content Domain 6: Security and Compliance domain, which accounts for 17% of the DOP-C02 exam. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 12–20 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
17%of the exam
Questions 11–15
- 11
What is the primary goal of the least privilege principle in IAM policy design?
Select an answer first - 12
Which IAM policy element is used to implement attribute-based access control (ABAC)?
Select an answer first - 13
A company wants to allow its employees to sign in to AWS using their existing corporate credentials. Which IAM feature should be used to establish this federation?
Select an answer first - 14
A company wants to grant developers access to EC2 instances based on the `Environment` tag (e.g., `dev`, `prod`). Developers should only be able to manage instances with the `Environment` tag matching their own user tag. What is the most scalable way to implement this?
Select an answer first - 15
What is the purpose of enforcing multi-factor authentication (MFA) for IAM users?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DOP-C02” is a trademark of its owner, used for identification only.