Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 326 discussion

A company is rearchitecting its applications to run on AWS. The company’s infrastructure includes multiple Amazon EC2 instances. The company's development team needs different levels of access. The company wants to implement a policy that requires all Windows EC2 instances to be joined to an Active Directory domain on AWS. The company also wants to implement enhanced security processes such as multi-factor authentication (MFA). The company wants to use managed AWS services wherever possible.

Which solution will meet these requirements?

  • A. Create an AWS Directory Service for Microsoft Active Directory implementation. Launch an Amazon Workspace. Connect to and use the Workspace for domain security configuration tasks.
  • B. Create an AWS Directory Service for Microsoft Active Directory implementation. Launch an EC2 instance. Connect to and use the EC2 instance for domain security configuration tasks.
  • C. Create an AWS Directory Service Simple AD implementation. Launch an EC2 instance. Connect to and use the EC2 instance for domain security configuration tasks.
  • D. Create an AWS Directory Service Simple AD implementation. Launch an Amazon Workspace. Connect to and use the Workspace for domain security configuration tasks.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
HappyPrince
Highly Voted 11 months, 1 week ago
Selected Answer: B
I support B as well per this link where EC2 is recommended: https://docs.aws.amazon.com/workspaces/latest/adminguide/directory_administration.html
upvoted 10 times
...
nublit
Highly Voted 11 months, 3 weeks ago
Selected Answer: B
B is correct. The question mention "Windows EC2", no "Windows user desktops". Maybe the Windows EC2 can be Windows Servers.
upvoted 9 times
...
AzureDP900
Most Recent 1 week ago
B is right The company wants to join all Windows EC2 instances to an Active Directory domain on AWS, which requires a full-featured Active Directory service. Using AWS Directory Service for Microsoft Active Directory (Enterprise edition) meets this requirement by providing a managed directory service that can be used to manage and secure EC2 instances. Launching an EC2 instance allows the development team to configure and test domain security configurations in a controlled environment, which is essential for ensuring the correct configuration of the Active Directory
upvoted 1 times
...
0b43291
1 week, 6 days ago
Selected Answer: A
Option A meets the requirements by using AWS Directory Service for Microsoft Active Directory, a managed service for hosting a full Active Directory domain. It also leverages Amazon WorkSpaces, a managed desktop service supporting MFA, for secure administrative access to configure the Active Directory domain, aligning with the company's preference for managed AWS services. Option B: While creating an AWS Directory Service for Microsoft Active Directory implementation is correct, launching an EC2 instance for domain security configuration tasks is not the most suitable approach. EC2 instances require additional management overhead, and the company wants to use managed services wherever possible.
upvoted 1 times
...
Daniel76
3 weeks, 2 days ago
Selected Answer: B
Add a vote to B as it is dangerously swaying to A. The EC2 instances referred to should be the managed domain controller to manage EC2 instances that join the domain, to push down GPO policies etc. You can launch more than one for HA. https://aws.amazon.com/blogs/security/how-to-increase-the-redundancy-and-performance-of-your-aws-directory-service-for-microsoft-ad-directory-by-adding-domain-controllers/
upvoted 1 times
...
sashenka
1 month ago
Selected Answer: A
Answer is A: Amazon WorkSpaces is a managed desktop-as-a-service solution that aligns with the requirement to use managed services: - Provides a managed alternative to running EC2 instances - Integrates seamlessly with AWS Managed Microsoft AD. - Reduces administrative overhead compared to managing EC2 instances
upvoted 1 times
...
ctrue
4 months ago
B is correct, it is application infrastructure, not for desktop.
upvoted 1 times
...
junehc
4 months, 2 weeks ago
I will go for A based on this "RADIUS MFA is applicable only to authenticate access to the AWS Management Console, or to Amazon Enterprise applications and services such as WorkSpaces, Amazon QuickSight, or Amazon Chime. It does not provide MFA to Windows workloads running on EC2 instances, or for signing into an EC2 instance" https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ad_connector_mfa.html
upvoted 1 times
...
Win007
5 months, 2 weeks ago
A is correct
upvoted 1 times
...
trungtd
5 months, 2 weeks ago
Selected Answer: A
Technically, you can use AWS Workspace for domain security configuration tasks. So A is correct
upvoted 3 times
...
9f02c8d
5 months, 3 weeks ago
A is right answer
upvoted 1 times
...
9f02c8d
6 months ago
A is right answer as the Amazon WorkSpaces provides a managed desktop-as-a-service solution that allows you to access a Windows desktop environment in the AWS Cloud
upvoted 1 times
...
paderni
6 months ago
A. Amazon WorkSpaces is more secure and managed,
upvoted 1 times
...
markovr6
6 months, 3 weeks ago
You can managed AD Admin tasks from Workspace. The requirement is to use AWS Managed Services where possible. So answer is A - nothing you can manage AD wise on EC2 that you can't do on the Windows Workspace
upvoted 1 times
...
titi_r
7 months, 2 weeks ago
Selected Answer: A
A - correct.
upvoted 1 times
...
TonytheTiger
8 months, 1 week ago
Selected Answer: A
Option A - Three requirements, 1. join AD domain, 2. enable MFA, 3. Use AWS managed service. Nothing about cost or any additional requirements. Option A checks all the boxes from the article information - https://aws.amazon.com/blogs/security/how-to-enable-multi-factor-authentication-for-amazon-workspaces-and-amazon-quicksight-by-using-microsoft-ad-and-on-premises-credentials/
upvoted 5 times
...
Dgix
8 months, 3 weeks ago
Selected Answer: A
Because managed services.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...