AmazonAmazon DevOps Engineer Professional DOP-C02 Certification ·EN ·Updated 4 Aug 2026

An organization uses AWS Organizations with a root OU and a child OU. The root OU's SCP allows all actions on all resources. The child OU's SCP allows all DynamoDB and Lambda actions and denies all other actions. There is an account named vendor-data in the child OU. An IAM user in that account has the AdministratorAccess IAM policy but receives AccessDenied when attempting to launch an EC2 instance. What change should be made so the IAM user can launch EC2 instances in the vendor-data account?

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 4 August 2026 · Source: official academy
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product