AWS Certified Developer Associate DVA-C01 – Question374

A company wants to make sure that only one user from its Admin group has the permanent right to delete an Amazon EC2 resource. There should be no changes in the existing policy under the Admin group.
What should a developer use to meet these requirements?

A.
AWS managed policy
B. Inline policy
C. IAM trust relationship
D. AWS Security Token Service (AWS STS)