Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 53 Topic 6 Discussion

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 53 Topic 6 Discussion

DOP-C02 Exam Topic 6 Question 53 Discussion:
Question #: 53
Topic #: 6

A company uses AWS Organizations to manage its AWS accounts. The organization root has a child OU that is named Department. The Department OU has a child OU that is named Engineering. The default FullAWSAccess policy is attached to the root, the Department OU. and the Engineering OU.

The company has many AWS accounts in the Engineering OU. Each account has an administrative 1AM role with the AdmmistratorAccess 1AM policy attached. The default FullAWSAccessPolicy is also attached to each account.

A DevOps engineer plans to remove the FullAWSAccess policy from the Department OU The DevOps engineer will replace the policy with a policy that contains an Allow statement for all Amazon EC2 API operations.

What will happen to the permissions of the administrative 1AM roles as a result of this change'?


A.

All API actions on all resources will be allowed


B.

All API actions on EC2 resources will be allowed. All other API actions will be denied.


C.

All API actions on all resources will be denied


D.

All API actions on EC2 resources will be denied. All other API actions will be allowed.


Get Premium DOP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.