
AWSCertified DevOps Engineer - Professional
Domain 6Objective 1
Task Statement 6.1: Implement Techniques for Identity and Access Management at Scale. DOP-C02 Practice Questions (Page 4)
Part of the Content Domain 6: Security and Compliance domain, which accounts for 17% of the DOP-C02 exam. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 12–20 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
17%of the exam
Questions 16–20
- 16
In AWS IAM, how is RBAC typically implemented for human users?
Select an answer first - 17
Which AWS service provides centralized access management and single sign-on (SSO) across multiple AWS accounts and business applications?
Select an answer first - 18
A company has a team of developers who need to create IAM roles for their applications. The developers should be able to create roles and attach policies, but they must not be able to grant themselves or others permissions beyond a predefined set of AWS services. What should the company implement?
Select an answer first - 19
A company has a production IAM role that grants broad permissions to manage EC2 instances. A DevOps engineer needs to temporarily use this role to perform a specific maintenance task that only requires stopping and starting instances. The engineer wants to ensure that they cannot perform any other actions during this session. What is the most secure way to achieve this?
Select an answer first - 20
Where are service control policies (SCPs) applied in AWS Organizations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DOP-C02” is a trademark of its owner, used for identification only.