exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 826 discussion

A company is migrating applications from an on-premises Microsoft Active Directory that the company manages to AWS. The company deploys the applications in multiple AWS accounts. The company uses AWS Organizations to manage the accounts centrally.

The company's security team needs a single sign-on solution across all the company's AWS accounts. The company must continue to manage users and groups that are in the on-premises Active Directory.

Which solution will meet these requirements?

  • A. Create an Enterprise Edition Active Directory in AWS Directory Service for Microsoft Active Directory. Configure the Active Directory to be the identity source for AWS IAM Identity Center.
  • B. Enable AWS IAM Identity Center. Configure a two-way forest trust relationship to connect the company's self-managed Active Directory with IAM Identity Center by using AWS Directory Service for Microsoft Active Directory.
  • C. Use AWS Directory Service and create a two-way trust relationship with the company's self-managed Active Directory.
  • D. Deploy an identity provider (IdP) on Amazon EC2. Link the IdP as an identity source within AWS IAM Identity Center.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LeonSauveterre
3 months ago
Selected Answer: B
AWS IAM Identity Center (formerly AWS SSO): Provides SSO across multiple AWS accounts in an organization. By configuring a 2-way forest trust relationship between the on-premises AD and MAD, IAM Identity Center can integrate seamlessly with the existing AD to manage authentication and authorization, allowing the company to retain its existing on-premises AD as the primary identity source while extending to AWS. A - This creates a separate directory in AWS, requiring migration of users and groups, which fails to continue using the on-premises AD. C - IAM Identity Center is still needed for SSO (single sign-on) functionality. D - OK but so much overhead.
upvoted 2 times
...
LuongTo
5 months ago
why C is out?
upvoted 1 times
...
EdricHoang
9 months, 1 week ago
Selected Answer: B
"continue to manage users and groups that are in the on-premises Active Directory" I go for B
upvoted 2 times
...
Scheldon
9 months, 3 weeks ago
Selected Answer: B
AnswerB AWS Directory Service lets you run Microsoft Active Directory (AD) as a managed service. AWS Directory Service for Microsoft Active Directory, also referred to as AWS Managed Microsoft AD, is powered by Windows Server 2019. With AWS Managed Microsoft AD, you can run directory-aware workloads in the AWS Cloud, including Microsoft SharePoint and custom .NET and SQL Server-based applications. You can also configure a trust relationship between AWS Managed Microsoft AD in the AWS Cloud and your existing on-premises Microsoft Active Directory, providing users and groups with access to resources in either domain, using AWS IAM Identity Center. https://docs.aws.amazon.com/directoryservice/latest/admin-guide/directory_microsoft_ad.html
upvoted 2 times
...
Kaula
1 year ago
Selected Answer: B
https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_setup_trust.html
upvoted 4 times
...
haci
1 year ago
Selected Answer: B
Same with Q-28
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago