DOP-C02 Exam Question 111

A company uses Amazon S3 to store proprietary information. The development team creates buckets for new projects on a daily basis. The security team wants to ensure that all existing and future buckets have encryption logging and versioning enabled. Additionally, no buckets should ever be publicly read or write accessible.
What should a DevOps engineer do to meet these requirements?
  • DOP-C02 Exam Question 112

    A DevOps engineer is working on a project that is hosted on Amazon Linux and has failed a security review.
    The DevOps manager has been asked to review the company buildspec. yaml die for an AWS CodeBuild project and provide recommendations. The buildspec. yaml file is configured as follows:

    What changes should be recommended to comply with AWS security best practices? (Select THREE.)
  • DOP-C02 Exam Question 113

    A SaaS company uses ECS (Fargate) behind an ALB and CodePipeline + CodeDeploy for blue/green deployments. They need automatic, incremental traffic shifting over time with no downtime.
    Which solution will meet these requirements?
  • DOP-C02 Exam Question 114

    A company has an organization in AWS Organizations for its multi-account environment. A DevOps engineer is developing an AWS CodeArtifact based strategy for application package management across the organization. Each application team at the company has its own account in the organization. Each application team also has limited access to a centralized shared services account.
    Each application team needs full access to download, publish, and grant access to its own packages. Some common library packages that the application teams use must also be shared with the entire organization.
    Which combination of steps will meet these requirements with the LEAST administrative overhead? (Select THREE.)
  • DOP-C02 Exam Question 115

    A company has an organization in AWS Organizations. The organization includes workload accounts that contain enterprise applications. The company centrally manages users from an operations account. No users can be created in the workload accounts. The company recently added an operations team and must provide the operations team members with administrator access to each workload account.
    Which combination of actions will provide this access? (Choose three.)