exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 15 discussion

Exam question from Amazon's AWS-SysOps
Question #: 15
Topic #: 1
[All AWS-SysOps Questions]

The majority of your Infrastructure is on premises and you have a small footprint on AWS Your company has decided to roll out a new application that is heavily dependent on low latency connectivity to LOAP for authentication Your security policy requires minimal changes to the company's existing application user management processes.
What option would you implement to successfully launch this application1?

  • A. Create a second, independent LOAP server in AWS for your application to use for authentication
  • B. Establish a VPN connection so your applications can authenticate against your existing on-premises LDAP servers
  • C. Establish a VPN connection between your data center and AWS create a LDAP replica on AWS and configure your application to use the LDAP replica for authentication
  • D. Create a second LDAP domain on AWS establish a VPN connection to establish a trust relationship between your new and existing domains and use the new domain for authentication
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DAAJ
5 months ago
https://docs.aws.amazon.com/whitepapers/latest/best-practices-deploying-amazon-workspaces/ad-ds-deployment-scenarios.html Scenario 2 applies here and hence the correct answer is C- create a replica. VPN connection does not guarantee low latency. Creating a replica does not require much changes, if any, to existing on-premise LDAP service. Replica reduces latency of authentication/query requests to AD DS and the AD DS global catalog.
upvoted 1 times
...
ablazleon
1 year, 7 months ago
Selected Answer: B
Laauch a new application => "AD Connector cannot be used with your custom applications, as it is only used for secure AWS integration for the three use-cases mentioned above. Custom applications relying on your on-premises Active Directory should communicate with your domain controllers directly" https://aws.amazon.com/blogs/security/how-to-connect-your-on-premises-active-directory-to-aws-using-ad-connector/
upvoted 3 times
...
Shaktimaan
1 year, 11 months ago
B is correct. LDAP should not be replicated.
upvoted 1 times
...
TroyMcLure
2 years ago
Correct Answer: C Establish a VPN connection between your data center and AWS create a LDAP replica on AWS and configure your application to use the LDAP replica for authentication. Since the new application will reside in AWS and it is heavily dependent on low latency connectivity to LOAP for authentication, better use a read replica.
upvoted 2 times
albert_kuo
5 months, 1 week ago
because of low latency requirement, I voted for C
upvoted 1 times
...
...
FHU
2 years, 1 month ago
Letter B is correct. I don't think it is recommended to replicate LDAP data to AWS, like the other letters A, C and D are doing. https://aws.amazon.com/blogs/security/how-to-connect-your-on-premises-active-directory-to-aws-using-ad-connector/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago