
AWSCertified DevOps Engineer - Professional
Domain 6Objective 1
Task Statement 6.1: Implement Techniques for Identity and Access Management at Scale. DOP-C02 Practice Questions (Page 5)
Part of the Content Domain 6: Security and Compliance domain, which accounts for 17% of the DOP-C02 exam. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 12–20 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
12concepts
17%of the exam
Questions 21–25
- 21
What is the primary benefit of using AWS Secrets Manager for machine identity credentials?
Select an answer first - 22
A company with 2,000 employees uses Okta as its corporate identity provider. The company is migrating to AWS and wants employees to access the AWS Management Console using their existing Okta credentials, without creating IAM users. They also want to enforce MFA for all console access. Which solution should they implement?
Select an answer first - 23
What is the purpose of a service control policy (SCP) in AWS Organizations?
Select an answer first - 24
How can an administrator enforce MFA for IAM users in AWS?
Select an answer first - 25
A company wants to federate its existing identity provider (IdP) with AWS to allow users to sign in with their corporate credentials. Which AWS feature is used to establish this federation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DOP-C02” is a trademark of its owner, used for identification only.