AWS Certified DevOps Engineer - Professional DOP-C02 — Question 351
Topic 1 · Question 351 of 431
Topic 1 · Question 351 · Select all that apply
A company uses an organization in AWS Organizations to manage multiple AWS accounts in a hierarchical structure. An SCP that is associated with the organization root allows IAM users to be created. A DevOps team must be able to create IAM users with any level of permissions. Developers must also be able to create IAM users. However, developers must not be able to grant new IAM users excessive permissions. The developers have the CreateAndManageUsers role in each account. The DevOps team must be able to prevent other users from creating IAM users. Which combination of steps will meet these requirements? (Choose two.)
Select 2 answers to reveal the result.