SOA-C02 exam dumps

SOA-C02 practice question 173 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 173

Select 3

A company wants to allow external users to securely access resources in their AWS account. The users belong to an external identity provider (IdP) using SAML 2.0. Which combination of steps should the SysOps Administrator take to implement this solution?

  1. A

    Create a SAML provider in IAM and upload the IdP's metadata document.

  2. B

    Configure a trust relationship between the SAML provider and the IAM roles for access.

  3. C

    Create an IAM policy to allow the IdP to directly access AWS resources.

  4. D

    Ensure users authenticate with the IdP and receive temporary credentials via AssumeRoleWithSAML.

  5. E

    Enable multi-factor authentication (MFA) for all IAM users in the account.

Show answer and explanation

Correct answers: A, B, D

Explanation

To enable external users from a SAML-compliant IdP to access AWS resources, the SysOps Administrator needs to create a SAML provider in IAM and upload the IdP's metadata. Then, a trust relationship must be established between the SAML provider and specific IAM roles. When users authenticate with the IdP, they can assume those roles via the AssumeRoleWithSAML API, which provides temporary credentials to access AWS resources. MFA for IAM users is not relevant to this SAML-based federation scenario.

  • A. Correct.

    Correct: Creating a SAML provider in IAM and uploading the IdP's metadata document establishes a connection between AWS and the external IdP.

  • B. Correct.

    Correct: A trust relationship must be configured between the SAML provider and the IAM roles to grant the external users permissions to access AWS resources.

  • C. Incorrect.

    Incorrect: IAM policies do not allow granting direct resource access to an external IdP. IAM roles and trust relationships are required for this use case.

  • D. Correct.

    Correct: External users must authenticate with the IdP. The AssumeRoleWithSAML API is used to obtain temporary credentials for accessing AWS resources.

  • E. Incorrect.

    Incorrect: Enabling MFA for IAM users is unrelated to this scenario, as the external users are authenticated through the IdP rather than IAM users.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam