exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 28 discussion

A company is migrating applications to AWS. The applications are deployed in different accounts. The company manages the accounts centrally by using AWS Organizations. The company's security team needs a single sign-on (SSO) solution across all the company's accounts. The company must continue managing the users and groups in its on-premises self-managed Microsoft Active Directory.
Which solution will meet these requirements?

  • A. Enable AWS Single Sign-On (AWS SSO) from the AWS SSO console. Create a one-way forest trust or a one-way domain trust to connect the company's self-managed Microsoft Active Directory with AWS SSO by using AWS Directory Service for Microsoft Active Directory.
  • B. Enable AWS Single Sign-On (AWS SSO) from the AWS SSO console. Create a two-way forest trust to connect the company's self-managed Microsoft Active Directory with AWS SSO by using AWS Directory Service for Microsoft Active Directory.
  • C. Use AWS Directory Service. Create a two-way trust relationship with the company's self-managed Microsoft Active Directory.
  • D. Deploy an identity provider (IdP) on premises. Enable AWS Single Sign-On (AWS SSO) from the AWS SSO console.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
17Master
Highly Voted 2 years, 1 month ago
Selected Answer: B
Tricky question!!! forget one-way or two-way. In this scenario, AWS applications (Amazon Chime, Amazon Connect, Amazon QuickSight, AWS Single Sign-On, Amazon WorkDocs, Amazon WorkMail, Amazon WorkSpaces, AWS Client VPN, AWS Management Console, and AWS Transfer Family) need to be able to look up objects from the on-premises domain in order for them to function. This tells you that authentication needs to flow both ways. This scenario requires a two-way trust between the on-premises and AWS Managed Microsoft AD domains. It is a requirement of the application Scenario 2: https://aws.amazon.com/es/blogs/security/everything-you-wanted-to-know-about-trusts-with-aws-managed-microsoft-ad/
upvoted 74 times
aatikah
1 week, 4 days ago
Application Context in This Scenario: AWS Applications Mentioned in the Scenario: The question focuses on AWS Single Sign-On (AWS SSO) and the use of SSO across AWS accounts. AWS SSO with AWS Organizations does not require AWS applications to look up or access on-premises AD objects beyond authentication. Blog Reference: The blog mentions the need for a two-way trust if AWS services like Amazon WorkSpaces or Amazon WorkMail require access to user attributes stored in the on-premises AD. This scenario does not mention such AWS applications, so a one-way trust is sufficient for the SSO use case.
upvoted 1 times
...
mohamedsambo
11 months, 3 weeks ago
AWS IAM Identity Center requires a two-way trust so that it has permissions to read user and group information from your domain to synchronize user and group metadata. IAM Identity Center uses this metadata when assigning access to permission sets or applications. User and group metadata is also used by applications for collaboration, like when you share a dashboard with another user or group. The trust from AWS Directory Service for Microsoft Active Directory to your domain permits IAM Identity Center to trust your domain for authentication. The trust in the opposite direction grants AWS permissions to read user and group metadata.
upvoted 6 times
...
pbpally
1 year, 7 months ago
The problem with this is that nowhere in the question is it saying that the application needs to be able to flow back so two-way is not needed.
upvoted 4 times
...
pbpally
1 year, 7 months ago
What I did find though was documentation that explicitly states that IAM Identity Center (successor to AWS SSO) requires a two-way trust: https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_setup_trust.html
upvoted 10 times
...
...
KADSM
Highly Voted 2 years, 1 month ago
Answer B as we have AWS SSO which requires two way trust. As per documentation - A two-way trust is required for AWS Enterprise Apps such as Amazon Chime, Amazon Connect, Amazon QuickSight, AWS IAM Identity Center (successor to AWS Single Sign-On), Amazon WorkDocs, Amazon WorkMail, Amazon WorkSpaces, and the AWS Management Console. AWS Managed Microsoft AD must be able to query the users and groups in your self-managed AD. Amazon EC2, Amazon RDS, and Amazon FSx will work with either a one-way or two-way trust.
upvoted 14 times
pbpally
1 year, 7 months ago
I found the documentation that explicitly states that IAM Identity Center (successor to AWS SSO) requires a two-way trust: https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_setup_trust.html
upvoted 6 times
...
...
aatikah
Most Recent 1 week, 4 days ago
Selected Answer: A
Application Context in This Scenario: AWS Applications Mentioned in the Scenario: The question focuses on AWS Single Sign-On (AWS SSO) and the use of SSO across AWS accounts. AWS SSO with AWS Organizations does not require AWS applications to look up or access on-premises AD objects beyond authentication. This scenario does not mention such AWS applications, so a one-way trust is sufficient for the SSO use case.
upvoted 1 times
...
Carlini2020
1 month, 1 week ago
Selected Answer: A
No need for both ways communication.
upvoted 1 times
...
trinh_le
1 month, 1 week ago
Selected Answer: B
A specific aws applications require two-way trust. To migrate to the aws, we need all apps are available. So I pick B
upvoted 1 times
...
mzeynalli
2 months ago
Selected Answer: A
A. Enable AWS Single Sign-On (AWS SSO) from the AWS SSO console. Create a one-way forest trust or a one-way domain trust to connect the company's self-managed Microsoft Active Directory with AWS SSO by using AWS Directory Service for Microsoft Active Directory. Two-way trust (as mentioned in option B) allows mutual trust between both environments, which is not necessary if the company only wants AWS to authenticate against the on-premises AD. A two-way trust is not necessary if the company only needs authentication from the on-premises AD. It may introduce unnecessary complexity and potential security risks since it requires trust in both directions.
upvoted 1 times
...
MatAlves
3 months ago
Current version of this question (with Identity Center) doesn't even contain option A. https://www.examtopics.com/discussions/amazon/view/136806-exam-aws-certified-solutions-architect-associate-saa-c03/
upvoted 4 times
...
DwarfBaggins
4 months ago
Selected Answer: B
key word: Self Managed. https://docs.aws.amazon.com/singlesignon/latest/userguide/connectonpremad.html
upvoted 2 times
...
rpmaws
4 months ago
Selected Answer: A
Two way trust is not required here.
upvoted 1 times
HoaHK
3 months, 4 weeks ago
Right, but with Active Directory, two-way trust is require
upvoted 5 times
...
...
PoolDead
4 months, 4 weeks ago
Selected Answer: B
Option B (enabling AWS SSO and creating a two-way forest trust) is the appropriate solution based on the requirement for a two-way trust to support AWS enterprise applications and provide single sign-on capabilities across all AWS accounts while integrating with the on-premises Microsoft Active Directory.
upvoted 3 times
...
ChymKuBoy
6 months, 1 week ago
Selected Answer: B
B for sure
upvoted 1 times
...
Gape4
6 months, 2 weeks ago
Options A is enough and will make it work.
upvoted 1 times
...
OBIOHAnze
7 months ago
Selected Answer: A
Option A suggests enabling AWS SSO and using a one-way trust, which allows AWS SSO to rely on the on-premises Microsoft Active Directory for authentication while keeping the management centralized in AWS SSO. This is a common and recommended approach for integrating on-premises Active Directory with AWS SSO.
upvoted 2 times
...
firsttimetesttaker
8 months, 2 weeks ago
Selected Answer: A
For the sake of exam options A is enough. Option B rather increases security risk surface.
upvoted 2 times
...
awsgeek75
11 months, 2 weeks ago
Selected Answer: B
I'll go for B as A feels incomplete C Can be done but company wants SSO, not a fill director service D On prem already has a IDP so no.
upvoted 4 times
...
A_jaa
11 months, 2 weeks ago
Selected Answer: B
Answer-B
upvoted 1 times
...
boooliyooo
12 months ago
Selected Answer: D
D is better and more applicable in real-world context where everyone chooses simplicity over a overhaul solution; Where Organizations may prefer to continue using their existing, trusted on-premises IdP solutions for authentication, especially if they have specific security policies or compliance requirements.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago