SAA-C03 exam dumps

SAA-C03 practice question 18 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 18

Single answer

A company wants to grant its employees access to multiple AWS accounts using their corporate credentials managed in Microsoft Active Directory (AD). The company also requires centralized management of user permissions across these accounts. How can the company achieve this using AWS services?

  1. A

    Use AWS IAM Identity Center (AWS Single Sign-On) integrated with Microsoft Active Directory to manage federated access and assign permissions to users across AWS accounts.

  2. B

    Create individual IAM users in each AWS account and configure the IAM users to authenticate against Microsoft Active Directory.

  3. C

    Configure an Amazon Cognito user pool to integrate with Microsoft Active Directory and use it to provide access across AWS accounts.

  4. D

    Set up a custom identity broker application that integrates with Microsoft Active Directory and uses AssumeRole API calls to grant access to AWS accounts.

Show answer and explanation

Correct answer: A

Explanation

AWS IAM Identity Center (AWS Single Sign-On) is the recommended service for centrally managing federated access to multiple AWS accounts using corporate credentials. It integrates with Microsoft Active Directory to authenticate users and provides a centralized interface for managing permissions across accounts. This approach simplifies access management and eliminates the need for creating individual IAM users or custom identity broker applications.

  • A. Correct.

    This is the correct solution. AWS IAM Identity Center (AWS Single Sign-On) provides a way to centrally manage access to multiple AWS accounts and integrates seamlessly with Microsoft Active Directory for federated authentication. Users can access AWS accounts and services using their corporate credentials, and permissions can be assigned centrally using the AWS Management Console.

  • B. Incorrect.

    This is incorrect. Creating individual IAM users in each AWS account would require significant manual effort and does not leverage federated access or centralized permission management. It also defeats the purpose of using Microsoft Active Directory for authentication.

  • C. Incorrect.

    This is incorrect. Amazon Cognito is primarily used for managing user authentication for web and mobile apps, not for centralizing access to AWS accounts. It is not the ideal solution for integrating Microsoft Active Directory for federated access to AWS accounts.

  • D. Incorrect.

    This is incorrect. While a custom identity broker application could integrate with Microsoft Active Directory and use the AssumeRole API, developing and managing a custom broker adds unnecessary complexity. AWS IAM Identity Center offers a built-in solution to achieve this functionality without custom development.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam