Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "*"
    }
  ]
}

A DevOps engineer needs to create an IAM policy that allows a user to start and stop EC2 instances, but only for instances that have a specific tag 'Environment=Production'. The current policy allows all actions on all instances. Which modification must be made to enforce the tag-based restriction?

⚠ Common exam trap

Many exam-takers confuse `ec2:ResourceTag` (tag on the resource) with `aws:RequestTag` (tag in the API request) or `aws:PrincipalTag` (tag on the user), leading candidates to pick a condition key that does not evaluate the instance's existing tags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}

The `ec2:ResourceTag` condition key allows you to restrict actions based on the tags already attached to the EC2 instance. By using `StringEquals` with `ec2:ResourceTag/Environment` set to `Production`, the policy will only permit the `ec2:StartInstances` and `ec2:StopInstances` actions on instances that currently have that tag. This is the standard AWS mechanism for tag-based resource-level authorization in IAM policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a Condition block: "Condition": {"StringEquals": {"aws:PrincipalTag/Environment": "Production"}}

    Why it's wrong here

    This condition uses aws:PrincipalTag, which reads tags attached to the IAM principal (user or role) making the API call, not tags on the EC2 instance. As a result, it would allow the actions if the caller has a Production tag on their own user/role, regardless of whether the instance itself has that tag — so it fails to enforce the intended resource-level restriction and could grant access to non-Production instances. For EC2 resource controls, you must use ec2:ResourceTag/Environment instead.

  • ✗

    Change the Action to "ec2:Describe*" and add a NotAction element.

    Why it's wrong here

    This alternative changes the allowed actions to only ec2:Describe* and adds a NotAction element, but NotAction is meant for exclusionary deny statements, not for conditionally allowing a subset of actions on tagged resources. Moreover, ec2:Describe* calls are read-only and do not include the management operations the policy likely needs to permit, so the change would either over-broaden or break the intended permissions. To restrict specific actions to tagged instances, keep the Action list as-is and attach a Condition using ec2:ResourceTag/Environment.

  • ✓

    Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}

    Why this is correct

    This is correct because ec2:ResourceTag/Environment is the IAM condition key that checks the value of the Environment tag on the EC2 resource (instance, volume, etc.) that the request targets, and StringEquals ensures the tag must exactly equal "Production". By adding this Condition block to the policy statement, the allowed actions are only granted when the resource being acted upon carries that tag, effectively scoping permissions to Production instances. This is the standard pattern for tag-based, resource-level access control for EC2.

  • ✗

    Add a Condition block: "Condition": {"StringEquals": {"aws:RequestTag/Environment": "Production"}}

    Why it's wrong here

    The aws:RequestTag condition key inspects tags that are supplied in the API request itself, such as tags specified when creating an instance, not tags already existing on a resource. For actions that operate on an existing EC2 instance, the request typically does not include the instance's current tags, so this condition would always evaluate to false (or behave unpredictably) and would not restrict access to Production instances. Use ec2:ResourceTag to evaluate the resource's actual tags at authorization time.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.