Courseiva

DOP-C02 Security and Compliance Practice Question

Match each AWS security and identity service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manages users, groups, roles, and permissions

Creates and manages encryption keys

Rotates and manages secrets like database credentials

DDoS protection service

Web application firewall

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM: Manage user identities and permissions

IAM handles access control, AWS Organizations manages multi-account structure, and AWS Shield protects against DDoS attacks. The distractors incorrectly swap these definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IAM: Manage user identities and permissions

    Why this is correct

    AWS Identity and Access Management (IAM) is the service that provides identity and access management by creating users, groups, roles, and policies. It enables granular, least-privilege permissions for both human users and AWS services, and it integrates with external identity providers via SAML 2.0 and OIDC. IAM also issues temporary security credentials through AWS STS, making it the definitive mechanism for 'who can do what' within AWS accounts.

  • ✓

    AWS Organizations: Centrally manage multiple AWS accounts

    Why this is correct

    AWS Organizations is the governance service for managing multiple AWS accounts under a single management account. It enables hierarchical grouping using organizational units (OUs) and lets you apply service control policies (SCPs) that set upper permission boundaries for accounts, while also consolidating billing and enabling account creation via API. Its purpose is centralized administrative and cost oversight, not user-level identity management or network-layer threat mitigation.

  • ✓

    AWS Shield: Protect against DDoS attacks

    Why this is correct

    AWS Shield is a managed DDoS protection service that uses always-on detection and inline mitigation to defend against volumetric and state-exhaustion attacks at Layers 3 and 4. Shield Standard is included at no extra cost with AWS services like CloudFront and Route 53, while Shield Advanced adds enhanced protections, cost protection against scaling spikes, and access to the DDoS Response Team. It is purpose-built to preserve application availability during large-scale network attacks.

  • ✗

    IAM: Protect against DDoS attacks

    Why it's wrong here

    IAM's scope is the control plane of authentication and authorization; it has no visibility into network traffic, protocol analysis, or volumetric attack patterns. Assigning DDoS protection to IAM confuses the identity plane with the network plane—IAM policies grant or deny API actions, but they cannot inspect or filter inbound packets. Real DDoS mitigation is handled by AWS Shield, AWS WAF, and edge services like CloudFront and Global Accelerator, not by IAM.

  • ✗

    AWS Organizations: Manage user identities and permissions

    Why it's wrong here

    AWS Organizations uses service control policies (SCPs) to establish guardrails on what actions are allowed within member accounts, but it does not create or manage IAM users, groups, roles, or their individual permissions. SCPs function as boundary constraints that define the maximum allowable permissions, while actual user identity management remains entirely within IAM. Therefore, saying Organizations manages user identities mischaracterizes its governance role and conflates account-level policy with identity-level access control.

  • ✗

    AWS Shield: Centrally manage multiple AWS accounts

    Why it's wrong here

    AWS Shield operates exclusively in the network and application availability layer, monitoring traffic to detect and mitigate distributed denial-of-service attacks. It has no feature for creating accounts, organizing OUs, or applying service control policies—those are functions exclusive to AWS Organizations. Even if Shield Advanced can be centrally configured across accounts through the Shield console, that does not make it an account-management service; its mission is availability protection, not centralized multi-account oversight.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.