DOP-C02 Configuration Management and IaC Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:DescribeInstances",
"ec2:StartInstances",
"ec2:StopInstances"
],
"Resource": "*"
}
]
}A DevOps engineer needs to create an IAM policy that allows a user to start and stop EC2 instances, but only for instances that have a specific tag 'Environment=Production'. The current policy allows all actions on all instances. Which modification must be made to enforce the tag-based restriction?
⚠ Common exam trap
Many exam-takers confuse `ec2:ResourceTag` (tag on the resource) with `aws:RequestTag` (tag in the API request) or `aws:PrincipalTag` (tag on the user), leading candidates to pick a condition key that does not evaluate the instance's existing tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}
The `ec2:ResourceTag` condition key allows you to restrict actions based on the tags already attached to the EC2 instance. By using `StringEquals` with `ec2:ResourceTag/Environment` set to `Production`, the policy will only permit the `ec2:StartInstances` and `ec2:StopInstances` actions on instances that currently have that tag. This is the standard AWS mechanism for tag-based resource-level authorization in IAM policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a Condition block: "Condition": {"StringEquals": {"aws:PrincipalTag/Environment": "Production"}}
Why it's wrong here
This condition uses aws:PrincipalTag, which reads tags attached to the IAM principal (user or role) making the API call, not tags on the EC2 instance. As a result, it would allow the actions if the caller has a Production tag on their own user/role, regardless of whether the instance itself has that tag — so it fails to enforce the intended resource-level restriction and could grant access to non-Production instances. For EC2 resource controls, you must use ec2:ResourceTag/Environment instead.
- ✗
Change the Action to "ec2:Describe*" and add a NotAction element.
Why it's wrong here
This alternative changes the allowed actions to only ec2:Describe* and adds a NotAction element, but NotAction is meant for exclusionary deny statements, not for conditionally allowing a subset of actions on tagged resources. Moreover, ec2:Describe* calls are read-only and do not include the management operations the policy likely needs to permit, so the change would either over-broaden or break the intended permissions. To restrict specific actions to tagged instances, keep the Action list as-is and attach a Condition using ec2:ResourceTag/Environment.
- ✓
Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}
Why this is correct
This is correct because ec2:ResourceTag/Environment is the IAM condition key that checks the value of the Environment tag on the EC2 resource (instance, volume, etc.) that the request targets, and StringEquals ensures the tag must exactly equal "Production". By adding this Condition block to the policy statement, the allowed actions are only granted when the resource being acted upon carries that tag, effectively scoping permissions to Production instances. This is the standard pattern for tag-based, resource-level access control for EC2.
- ✗
Add a Condition block: "Condition": {"StringEquals": {"aws:RequestTag/Environment": "Production"}}
Why it's wrong here
The aws:RequestTag condition key inspects tags that are supplied in the API request itself, such as tags specified when creating an instance, not tags already existing on a resource. For actions that operate on an existing EC2 instance, the request typically does not include the instance's current tags, so this condition would always evaluate to false (or behave unpredictably) and would not restrict access to Production instances. Use ec2:ResourceTag to evaluate the resource's actual tags at authorization time.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.