DOP-C02 exam dumps

DOP-C02 practice question 362 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 362

Select 3

Your organization wants to enable single sign-on (SSO) for its employees to access AWS resources. The organization uses an on-premises Active Directory (AD) for identity management and prefers to avoid managing IAM users in AWS. They want to leverage their existing identity store while ensuring secure and seamless access to AWS Management Console and CLI. Which of the following steps are required to implement this solution?

  1. A

    Configure AWS IAM Identity Center (AWS SSO) and integrate it with your on-premises Active Directory using AWS Directory Service.

  2. B

    Create an IAM role with a trust policy that allows the identity provider to assume the role.

  3. C

    Set up a SAML-based identity provider in IAM and link it to your on-premises Active Directory.

  4. D

    Configure an Amazon Cognito user pool to manage federated access for your employees.

  5. E

    Assign permissions to the IAM role based on the access policies required by your employees.

Show answer and explanation

Correct answers: A, B, E

Explanation

To enable SSO for employees using an on-premises Active Directory, AWS IAM Identity Center (AWS SSO) is the recommended service for integration with the directory via AWS Directory Service. An IAM role is required to establish trust with the identity provider and assign permissions for AWS resource access. SAML-based identity providers and Amazon Cognito are alternative solutions but are not the best fit for this specific scenario.

  • A. Correct.

    Correct. AWS IAM Identity Center (AWS SSO) can be integrated with on-premises Active Directory through AWS Directory Service, allowing employees to use their existing credentials to access AWS resources.

  • B. Correct.

    Correct. An IAM role is required to define trust relationships with the identity provider and grant appropriate permissions to the federated users.

  • C. Incorrect.

    Incorrect. While SAML-based identity providers are an option, using AWS IAM Identity Center with AWS Directory Service is a simpler and more native integration for Active Directory in this scenario.

  • D. Incorrect.

    Incorrect. Amazon Cognito is primarily used for web and mobile app authentication and is not relevant for this scenario, which deals with Active Directory and AWS SSO.

  • E. Correct.

    Correct. Permissions must be assigned to the IAM role to define what actions and resources the federated users can access in AWS.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam