SAP-C02 exam dumps

SAP-C02 practice question 52 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 52

Single answer

An organization is using AWS IAM Identity Center (AWS Single Sign-On) to manage access to AWS accounts and applications for its employees. The organization wants to ensure that certain users have administrator access only to a specific AWS account, while ensuring least privilege access across other accounts. How can the organization achieve this using AWS IAM Identity Center?

  1. A

    Create a permission set in AWS IAM Identity Center with AdministratorAccess permissions and assign it only to the specific AWS account.

  2. B

    Use AWS Organizations' Service Control Policies (SCPs) to allow AdministratorAccess only for the specific AWS account.

  3. C

    Directly create IAM roles with AdministratorAccess in the specific AWS account and assign them to users via IAM Identity Center.

  4. D

    Create a permission set with AdministratorAccess in IAM Identity Center and assign it to all AWS accounts, then use IAM policies to restrict access in other accounts.

Show answer and explanation

Correct answer: A

Explanation

AWS IAM Identity Center (AWS Single Sign-On) enables centralized management of user access permissions across multiple AWS accounts and applications. To provide administrator access to a specific account, you create a permission set with the AdministratorAccess managed policy and assign it only to the relevant account. This ensures that least privilege is maintained for other accounts, aligning with best practices for security and access management.

  • A. Correct.

    This is the correct solution. By creating a permission set with AdministratorAccess in AWS IAM Identity Center and assigning it only to the specific AWS account, users can have admin access to that account while adhering to least privilege for other accounts.

  • B. Incorrect.

    SCPs are used to define permissions boundaries within AWS Organizations but cannot directly manage user or role permissions for specific accounts via IAM Identity Center.

  • C. Incorrect.

    While IAM roles could be created directly in the account, this approach bypasses the centralized management and benefits offered by AWS IAM Identity Center.

  • D. Incorrect.

    Assigning AdministratorAccess to all accounts does not follow the principle of least privilege, even if additional restrictions are applied through IAM policies.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam