Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 81 Topic 9 Discussion

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 81 Topic 9 Discussion

DOP-C02 Exam Topic 9 Question 81 Discussion:
Question #: 81
Topic #: 9

A company uses AWS Organizations to manage its AWS accounts. The company has a root OU that has a child OU. The root OU has an SCP that allows all actions on all resources. The child OU has an SCP that allows all actions for Amazon DynamoDB and AWS Lambda, and denies all other actions.

The company has an AWS account that is named vendor-data in the child OU. A DevOps engineer has an 1AM user that is attached to the AdministratorAccess 1AM policy in the vendor-data account. The DevOps engineer attempts to launch an Amazon EC2 instance in the vendor-data account but receives an access denied error.

Which change should the DevOps engineer make to launch the EC2 instance in the vendor-data account?


A.

Attach the AmazonEC2FullAccess 1AM policy to the 1AM user.


B.

Create a new SCP that allows all actions for Amazon EC2. Attach the SCP to the vendor-data account.


C.

Update the SCP in the child OU to allow all actions for Amazon EC2.


D.

Create a new SCP that allows all actions for Amazon EC2. Attach the SCP to the root OU.


Get Premium DOP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.