Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified DevOps Engineer - Professional

Domain 6Objective 1

Task Statement 6.1: Implement Techniques for Identity and Access Management at Scale. DOP-C02 Practice Questions (Page 7)

Part of the Content Domain 6: Security and Compliance domain, which accounts for 17% of the DOP-C02 exam. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 12–20 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
12concepts
17%of the exam

Questions 31–34

  1. 31foundation · easy

    What is the core idea behind role-based access control (RBAC) in AWS IAM?

    Select an answer first
  2. 32foundation · easy

    A DevOps engineer needs to grant an AWS service (such as an EC2 instance) permission to call other AWS services. Which IAM entity is designed for this machine access use case?

    Select an answer first
  3. 33application · medium

    A company uses AWS Organizations with multiple accounts. They want to ensure that no IAM user or role in any account can delete an S3 bucket that has a specific tag `Protected=true`. What is the most effective way to enforce this?

    Select an answer first
  4. 34foundation · easy

    Which STS API call is used to obtain temporary credentials for a role?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to DOP-C02

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DOP-C02” is a trademark of its owner, used for identification only.