ANS-C01 exam dumps

ANS-C01 practice question 263 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 263

Select 3

An organization wants to enable Single Sign-On (SSO) for its applications hosted in AWS using its on-premises Active Directory (AD). They want to use SAML 2.0 for authentication and ensure that users can seamlessly access AWS services without needing additional credentials. Which of the following configurations are required to achieve this?

  1. A

    Configure an identity provider (IdP) in AWS IAM with metadata from the on-premises Active Directory Federation Services (AD FS).

  2. B

    Set up a trust relationship between the AWS account and the on-premises AD by creating a dedicated VPC peering connection.

  3. C

    Create IAM roles with corresponding SAML permissions for users or groups mapped from the on-premises AD.

  4. D

    Deploy an AWS Directory Service Simple AD to synchronize users from the on-premises Active Directory.

  5. E

    Configure AWS Management Console and AWS CLI to use SAML tokens for federated access.

Show answer and explanation

Correct answers: A, C, E

Explanation

To enable SAML-based SSO between AWS and the on-premises Active Directory, the organization must configure an identity provider (IdP) in AWS IAM, create IAM roles mapped to SAML assertions from the AD, and ensure that AWS services such as the Management Console and CLI are configured to accept SAML tokens. A VPC peering connection or AWS Directory Service Simple AD is not required for this specific use case.

  • A. Correct.

    Correct. Configuring an identity provider (IdP) in AWS IAM using metadata from AD FS is necessary for integrating SAML-based authentication with AWS.

  • B. Incorrect.

    Incorrect. A VPC peering connection is not required for enabling federated authentication between AWS and an on-premises directory service.

  • C. Correct.

    Correct. IAM roles must be created and mapped to SAML assertions to grant users or groups appropriate permissions for accessing AWS resources.

  • D. Incorrect.

    Incorrect. AWS Directory Service Simple AD is not required for SAML-based authentication; it is typically used for directory-aware workloads in AWS.

  • E. Correct.

    Correct. Configuring AWS services to use SAML tokens ensures that federated users can seamlessly access AWS services via the AWS Management Console or CLI.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam