ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 43 - DOP-C02 discussion

Report
Export

A company has an organization in AWS Organizations. The organization includes workload accounts that contain enterprise applications. The company centrally manages users from an operations account. No users can be created in the workload accounts. The company recently added an operations team and must provide the operations team members with administrator access to each workload account.

Which combination of actions will provide this access? (Choose three.)

A.
Create a SysAdmin role in the operations account. Attach the AdministratorAccess policy to the role. Modify the trust relationship to allow the sts:AssumeRole action from the workload accounts.
Answers
A.
Create a SysAdmin role in the operations account. Attach the AdministratorAccess policy to the role. Modify the trust relationship to allow the sts:AssumeRole action from the workload accounts.
B.
Create a SysAdmin role in each workload account. Attach the AdministratorAccess policy to the role. Modify the trust relationship to allow the sts:AssumeRole action from the operations account.
Answers
B.
Create a SysAdmin role in each workload account. Attach the AdministratorAccess policy to the role. Modify the trust relationship to allow the sts:AssumeRole action from the operations account.
C.
Create an Amazon Cognito identity pool in the operations account. Attach the SysAdmin role as an authenticated role.
Answers
C.
Create an Amazon Cognito identity pool in the operations account. Attach the SysAdmin role as an authenticated role.
D.
In the operations account, create an IAM user for each operations team member.
Answers
D.
In the operations account, create an IAM user for each operations team member.
E.
In the operations account, create an IAM user group that is named SysAdmins. Add an IAM policy that allows the sts:AssumeRole action for the SysAdmin role in each workload account. Add all operations team members to the group.
Answers
E.
In the operations account, create an IAM user group that is named SysAdmins. Add an IAM policy that allows the sts:AssumeRole action for the SysAdmin role in each workload account. Add all operations team members to the group.
F.
Create an Amazon Cognito user pool in the operations account. Create an Amazon Cognito user for each operations team member.
Answers
F.
Create an Amazon Cognito user pool in the operations account. Create an Amazon Cognito user for each operations team member.
Suggested answer: B, D, E

Explanation:

https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_cross-account-with-roles.html

asked 16/09/2024
samresh mahata
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first