20+ practice questions focused on Security and Compliance — one of the most tested topics on the AWS Certified DevOps Engineer Professional DOP-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security and Compliance PracticeA company is using AWS Organizations with multiple accounts. The Security team wants to centrally manage IAM roles that can be assumed by users in member accounts. Which solution should be used to enforce that only specific roles can be assumed across accounts, while ensuring that the policy updates are automatically applied to all accounts?
Explanation: It uses AWS CloudFormation StackSets to deploy IAM roles across member accounts with a trust policy that allows the Security account to assume them. StackSets ensure that role updates are automatically applied to all accounts in the organization. SCPs can be used in conjunction to enforce that only these specific roles can be assumed.
A company runs a multi-account environment using AWS Organizations. The security team has implemented a service control policy (SCP) that denies all actions on DynamoDB tables unless the request includes a specific tag "Environment": "Production". The development team has an IAM role with full DynamoDB access in their account. When they try to create a DynamoDB table using the AWS CLI, they receive an access denied error. They are certain they included the tag. The DevOps engineer reviews the SCP and finds that it uses the condition key "aws:RequestTag". However, the engineer notices that the SCP also denies access if the request does not include the tag for tagging actions. What is the most likely reason for the access denied error?
Explanation: The DynamoDB `CreateTable` API and the `aws dynamodb create-table` CLI command support the `Tags` parameter. Therefore, the SCP's `aws:RequestTag` condition can be satisfied by including the tag in the request. The denial described in the stem is not due to a lack of tagging support on CreateTable. None of the provided options gives a valid reason; the question is based on a false premise.
A DevOps engineer applies the S3 bucket policy shown in the exhibit to enforce encryption and secure transport. After applying the policy, users report that they can still upload objects without encryption. What is the most likely cause?
Explanation: The first Deny statement in the bucket policy uses a condition that checks if the `s3:x-amz-server-side-encryption` header is not equal to `aws:kms`. This condition only applies when the header is present. For uploads without any encryption header, the condition does not evaluate to true, so the Deny does not apply. Therefore, users can upload objects without encryption. The statement does not explicitly allow `AES256`, but rather fails to block requests that lack the encryption header entirely, which is the underlying reason why unencrypted uploads are permitted.
A company wants to centralize audit logs from multiple AWS accounts into a single S3 bucket. The logs must be encrypted at rest and access should be limited to the security team. Which solution is MOST secure and scalable?
Explanation: It enforces both encryption in transit (aws:SecureTransport) and encryption at rest (SSE-KMS) directly at the bucket policy level, while scoping access to a specific security team IAM role. This is the most secure and scalable approach because the policy is evaluated on every request regardless of which account or principal is writing, and it centralizes control in one place. Using a bucket policy with explicit Deny conditions ensures that even misconfigured clients cannot bypass encryption requirements.
A security audit reveals that EC2 instances have security groups with overly permissive inbound rules allowing all traffic (0.0.0.0/0) on SSH port 22. What is the BEST way to remediate this at scale?
Explanation: AWS Config with a managed rule can continuously monitor security groups for overly permissive rules and automatically remediate them using SSM Automation documents. This provides a scalable, auditable solution that enforces compliance across all regions and accounts. It is the best practice for remediation at scale because it integrates with AWS Organizations and can be deployed centrally.
+15 more Security and Compliance questions available
Practice all Security and Compliance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security and Compliance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security and Compliance questions on the DOP-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security and Compliance is tested as part of the AWS Certified DevOps Engineer Professional DOP-C02 blueprint. Practicing with targeted Security and Compliance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free DOP-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security and Compliance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security and Compliance practice session with instant scoring and detailed explanations.
Start Security and Compliance Practice →