DOP-C02 exam dumps

DOP-C02 practice question 361 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 361

Select 3

Your organization wants to enable its employees to access the AWS Management Console and other AWS resources using their corporate credentials from an existing Microsoft Active Directory. The organization also wants to enforce fine-grained access control and avoid the need for maintaining separate IAM user accounts for each employee. Which combination of approaches should you implement to achieve this?

  1. A

    Configure AWS IAM Identity Center to integrate with the corporate Active Directory using AWS Directory Service.

  2. B

    Set up an IAM Identity Provider with SAML and integrate it with the corporate Active Directory.

  3. C

    Use an IAM role with a trust policy that allows the SAML identity provider to assume the role.

  4. D

    Create individual IAM users for each employee and use Active Directory for password management.

  5. E

    Set up AWS Single Sign-On (SSO) to manage federated access independently of the corporate Active Directory.

Show answer and explanation

Correct answers: A, B, C

Explanation

To enable federated access to AWS resources using corporate credentials, you must integrate the corporate Active Directory with AWS services. AWS IAM Identity Center (formerly AWS Single Sign-On) is designed for this purpose and can connect to Active Directory using AWS Directory Service. Additionally, setting up an IAM Identity Provider with SAML and defining IAM roles with trust policies for the federated users ensures fine-grained access control. Creating individual IAM users or managing federation independently of the corporate directory would not meet the organization’s requirements.

  • A. Correct.

    Correct. AWS IAM Identity Center (formerly AWS Single Sign-On) can integrate with Active Directory via AWS Directory Service, enabling employees to use their corporate credentials for federated access.

  • B. Correct.

    Correct. Setting up an IAM Identity Provider with SAML allows you to federate access from the corporate Active Directory to AWS resources.

  • C. Correct.

    Correct. An IAM role with a trust policy enables federated users authenticated via the SAML identity provider to assume the role and gain access to AWS resources.

  • D. Incorrect.

    Incorrect. Creating individual IAM users for each employee would require additional management overhead and goes against the organization's goal of using corporate credentials for authentication.

  • E. Incorrect.

    Incorrect. AWS Single Sign-On is now part of IAM Identity Center, but configuring it independently of Active Directory would not meet the requirement to use corporate credentials.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam