SAP-C02 exam dumps

SAP-C02 practice question 54 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 54

Select 2

Your organization uses AWS IAM Identity Center (AWS Single Sign-On) to manage user access across multiple AWS accounts. Recently, a new compliance policy mandates that all IAM roles used by AWS IAM Identity Center must be restricted to specific AWS accounts and cannot be assumed by anyone outside of your organization. As a Solutions Architect, how would you enforce this requirement?

  1. A

    Configure a resource-based policy on IAM roles to allow access only from AWS IAM Identity Center's IP address range.

  2. B

    Use the 'Condition' element in the IAM role trust policy to allow access only from the specific AWS accounts managed by AWS IAM Identity Center.

  3. C

    Enable AWS Organizations Service Control Policies (SCPs) to restrict the 'sts:AssumeRole' action to allowed AWS accounts.

  4. D

    Use attribute-based access control (ABAC) in AWS IAM Identity Center to dynamically restrict access to roles based on user attributes.

  5. E

    Configure IAM role trust policies to validate that the principal assuming the role is coming from AWS IAM Identity Center.

Show answer and explanation

Correct answers: B, E

Explanation

To meet the compliance requirement of restricting IAM roles used by AWS IAM Identity Center to specific AWS accounts, the IAM role trust policy must be configured with conditions that validate the principal (AWS IAM Identity Center) and the AWS accounts allowed to assume the role. Using 'Condition' elements in the trust policy and specifying AWS IAM Identity Center as the principal ensures that only authorized accounts and entities can access the roles.

  • A. Incorrect.

    Incorrect: AWS IAM Identity Center does not use fixed IP address ranges for its operations. Resource-based policies cannot enforce restrictions based on IP addresses in this context.

  • B. Correct.

    Correct: Using the 'Condition' element in the IAM role trust policy, you can specify conditions such as the AWS account ID or the identity provider ARN to restrict access to specific AWS accounts.

  • C. Incorrect.

    Incorrect: While SCPs can help enforce organization-wide restrictions, they do not directly control IAM role trust policies or restrict principal access for AWS IAM Identity Center.

  • D. Incorrect.

    Incorrect: ABAC is useful for fine-grained access control based on attributes, but it is not applicable for configuring IAM role trust policies to restrict access to specific AWS accounts.

  • E. Correct.

    Correct: Configuring IAM role trust policies to ensure that only AWS IAM Identity Center principals can assume the role ensures that external entities cannot access the roles.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam