Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam DOP-C01 Topic 18 Question 84 Discussion

Actual exam question for Amazon's DOP-C01 exam
Question #: 84
Topic #: 18
[All DOP-C01 Questions]

A company's legacy application uses IAM user credentials to access resources in the company's AWS Organizations organization. A DevOps engineer needs to ensure new IAM users cannot be created unless the employee creating the IAM user is on an exception list.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Chun
8 months ago
I think option C or D might be the way to go. Using an EventBridge rule to trigger a Lambda function that checks the user against an exception list seems like a more flexible solution. That way, we can control who can create IAM users without having to rely on the Organizations SCP.
upvoted 0 times
Viva
7 months ago
B: So, option C it is then?
upvoted 0 times
...
Erinn
8 months ago
A: Definitely, especially when it comes to managing user credentials and access to resources.
upvoted 0 times
...
Timothy
8 months ago
B: It's always good to have multiple layers of security in place.
upvoted 0 times
...
Ira
8 months ago
A: Exactly, it gives us more control without having to rely solely on the Organizations SCP.
upvoted 0 times
...
Karina
8 months ago
B: I agree, having that flexibility to control who can create IAM users is important.
upvoted 0 times
...
Lorita
8 months ago
A: I think option C is the best choice here because it involves using an EventBridge rule and Lambda function to check against an exception list.
upvoted 0 times
...
...
Francisca
8 months ago
Option B does sound like it might work, but I'm a bit concerned about the condition using StringEquals. Wouldn't that allow users on the exception list to create IAM users, but not anyone else? I feel like we need something more restrictive.
upvoted 0 times
...
Casey
8 months ago
Yeah, I'm a bit confused too. It's not entirely clear to me what the best solution would be. I'm leaning towards option B, but I'm not sure if that's the right approach.
upvoted 0 times
...
Victor
8 months ago
This question seems pretty tricky. I'm not sure if I fully understand the requirements, but it sounds like we need to find a way to restrict IAM user creation unless the user is on an exception list.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77