ANS-C01 exam dumps

ANS-C01 practice question 264 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 264

Select 2

Your company has deployed an application in AWS that requires users to authenticate via single sign-on (SSO) using your on-premises Active Directory (AD). The application is hosted in an Amazon VPC, and you want to ensure that the user's authentication requests are securely handled and the user roles in AWS are tied to the AD groups. Which combination of actions should you take to implement this solution?

  1. A

    Configure an AWS Identity and Access Management (IAM) SAML provider with metadata from your on-premises Active Directory Federation Services (AD FS).

  2. B

    Set up an AWS Client VPN endpoint to connect users to the VPC securely.

  3. C

    Establish a trust relationship between the SAML provider and your AWS IAM roles.

  4. D

    Use an Amazon Cognito user pool to sync user credentials with Active Directory.

  5. E

    Enable SSO on the application by integrating it with AWS Application Load Balancer's native authentication feature.

Show answer and explanation

Correct answers: A, C

Explanation

To enable SAML-based SSO with on-premises Active Directory, you must configure an IAM SAML provider with AD FS metadata and establish trust between the provider and IAM roles. This allows users authenticated via AD to assume roles and access AWS resources securely. Other options, such as VPN endpoints or Cognito, are not directly relevant to SAML-based SSO with Active Directory in this scenario.

  • A. Correct.

    This is correct. To integrate your on-premises Active Directory with AWS for SSO, you need to configure an IAM SAML provider using metadata from AD FS.

  • B. Incorrect.

    This is incorrect. An AWS Client VPN endpoint is used for secure network connections, not for authentication or SSO.

  • C. Correct.

    This is correct. Establishing trust between the SAML provider and IAM roles is required to allow users authenticated via AD to assume specific roles in AWS.

  • D. Incorrect.

    This is incorrect. Amazon Cognito user pools are used for managing application users directly and are not required for integrating SAML with AD.

  • E. Incorrect.

    This is incorrect. AWS Application Load Balancer's native authentication is not necessary when using SAML-based SSO with an IAM SAML provider.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam