Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company is using AWS CloudFormation to deploy infrastructure. The security team wants to ensure that any changes to IAM roles must be reviewed and approved by a security engineer before deployment. The DevOps engineer needs to implement a gating mechanism. Which approach should the engineer use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CodePipeline that deploys CloudFormation stacks and include a manual approval step for changes that modify IAM resources.

AWS CodePipeline can include a manual approval step before deploying CloudFormation stacks, allowing the security engineer to review and approve any changes to IAM roles. Option A is incorrect because AWS Config only detects changes after they occur; it cannot prevent deployment. Option B is incorrect because a service control policy would deny all IAM role creation across the organization, which is too restrictive and not a gating mechanism. Option C is incorrect because requiring MFA for CloudFormation actions does not specifically gate changes to IAM resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Config to detect changes to IAM roles and trigger a Lambda function that reverts the change.

    Why it's wrong here

    AWS Config is a detective control: it evaluates resource configuration after the change has already been applied and then invokes a Lambda function for remediation. This is inherently reactive, meaning the unauthorized IAM role or assume-role policy exists in effect until the revert runs, creating a window for abuse. Additionally, the revert action can conflict with CloudFormation's drift detection, causing recurring reconciliation cycles and potential stack update failures. To be preventive, the review must happen before the template is deployed, not after the fact.

  • ✗

    Apply a service control policy that denies iam:CreateRole and iam:UpdateAssumeRolePolicy across the organization.

    Why it's wrong here

    An SCP denying iam:CreateRole and iam:UpdateAssumeRolePolicy across the entire organization would block all IAM role creation and assume-role policy updates, not just those performed by CloudFormation. This is overly broad and would break legitimate workflows such as service-linked role creation, application provisioning, and cross-account access. It also fails to address other IAM-modifying actions like iam:PutRolePolicy, iam:AttachRolePolicy, or iam:PassRole, which could still be used to grant excessive permissions. The goal is to enforce a review process, not to forbid all IAM changes.

  • ✗

    Add a condition to the IAM policy that requires MFA for any CloudFormation action.

    Why it's wrong here

    Requiring MFA for CloudFormation actions only strengthens the authentication factor; it does not introduce a secondary reviewer or any approval workflow. An authenticated user with MFA could still update a stack and modify IAM resources without any human oversight. The core requirement is separation of duties—ensuring a change is reviewed and approved by someone other than the requester—not merely proving possession of a hardware token or virtual MFA device. Therefore, MFA alone is insufficient to enforce the required change-management gate.

  • ✓

    Create a CodePipeline that deploys CloudFormation stacks and include a manual approval step for changes that modify IAM resources.

    Why this is correct

    A CodePipeline that deploys CloudFormation stacks can include a manual approval stage, which acts as a preventive control that pauses the pipeline before the stack update executes. The pipeline can detect when a change set modifies IAM resources—for example, by comparing the template or reviewing the change set—and conditionally require an approval step. This ensures a second person reviews the IAM changes before they are applied, satisfying the separation-of-duties requirement. Manual approval is a standard AWS pattern for production governance and is far more effective than post-hoc detection or MFA alone.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.