SAP-C02 exam dumps

SAP-C02 practice question 602 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 602

Single answer

Your organization has recently migrated to AWS and wants to centralize user authentication and authorization across multiple AWS accounts. The organization already uses Microsoft Active Directory (AD) on-premises for managing user identities. They also want to enable users to log in to the AWS Management Console using their existing AD credentials. Which solution will best meet these requirements?

  1. A

    Use AWS IAM Identity Center (AWS SSO) integrated with the on-premises Active Directory through AD Connector.

  2. B

    Enable AWS Directory Service Simple AD and synchronize it with the on-premises Active Directory for user authentication.

  3. C

    Set up AWS IAM roles in each account and create IAM users for each individual to match the on-premises AD users.

  4. D

    Deploy AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) and establish a trust relationship with the on-premises Active Directory.

Show answer and explanation

Correct answer: D

Explanation

To centralize authentication and authorization for multiple AWS accounts while leveraging existing on-premises Active Directory credentials, the best approach is to use AWS Managed Microsoft AD and establish a trust relationship with the on-premises AD. This setup allows users to authenticate using their existing AD credentials and provides centralized identity management suitable for multi-account environments.

  • A. Incorrect.

    This is incorrect because AWS IAM Identity Center (AWS SSO) does not directly integrate with on-premises Active Directory through AD Connector. Instead, AWS SSO integrates with AD through AWS Managed Microsoft AD or other identity providers.

  • B. Incorrect.

    This is incorrect because AWS Directory Service Simple AD does not support advanced Active Directory features like trust relationships or synchronization with on-premises Active Directory.

  • C. Incorrect.

    This is incorrect because managing individual IAM users for an entire organization is not scalable or secure for centralizing identity management across multiple accounts.

  • D. Correct.

    This is correct because AWS Managed Microsoft AD allows you to establish a trust relationship with your on-premises Active Directory, enabling seamless integration and the ability for users to authenticate using their existing credentials.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam