exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 70 discussion

A company has an environment that has a single AWS account. A solutions architect is reviewing the environment to recommend what the company could improve specifically in terms of access to the AWS Management Console. The company’s IT support workers currently access the console for administrative tasks, authenticating with named IAM users that have been mapped to their job role.

The IT support workers no longer want to maintain both their Active Directory and IAM user accounts. They want to be able to access the console by using their existing Active Directory credentials. The solutions architect is using AWS IAM Identity Center (AWS Single Sign-On) to implement this functionality.

Which solution will meet these requirements MOST cost-effectively?

  • A. Create an organization in AWS Organizations. Turn on the IAM Identity Center feature in Organizations. Create and configure a directory in AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) with a two-way trust to the company’s on-premises Active Directory. Configure IAM Identity Center and set the AWS Managed Microsoft AD directory as the identity source. Create permission sets and map them to the existing groups within the AWS Managed Microsoft AD directory.
  • B. Create an organization in AWS Organizations. Turn on the IAM Identity Center feature in Organizations. Create and configure an AD Connector to connect to the company’s on-premises Active Directory. Configure IAM Identity Center and select the AD Connector as the identity source. Create permission sets and map them to the existing groups within the company’s Active Directory.
  • C. Create an organization in AWS Organizations. Turn on all features for the organization. Create and configure a directory in AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) with a two-way trust to the company’s on-premises Active Directory. Configure IAM Identity Center and select the AWS Managed Microsoft AD directory as the identity source. Create permission sets and map them to the existing groups within the AWS Managed Microsoft AD directory.
  • D. Create an organization in AWS Organizations. Turn on all features for the organization. Create and configure an AD Connector to connect to the company’s on-premises Active Directory. Configure IAM Identity Center and set the AD Connector as the identity source. Create permission sets and map them to the existing groups within the company’s Active Directory.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
masetromain
Highly Voted 2 years, 2 months ago
Selected Answer: D
https://www.examtopics.com/discussions/amazon/view/69172-exam-aws-certified-solutions-architect-professional-topic-1/ You are correct, I apologize for the oversight. To meet the requirements of the IT support workers, option D would be the correct solution: This option will first enable all features in AWS Organizations, then create and configure an AD Connector to connect to the company's on-premises Active Directory. Then, it will configure IAM Identity Center (AWS SSO) and set the AD Connector as the identity source, allowing the IT support workers to access the console using their existing Active Directory credentials. Finally, it will create permission sets and map them to the existing groups within the company's Active Directory. This solution will also be cost-effective as it does not involve creating a new directory in AWS Directory Service.
upvoted 22 times
...
dev112233xx
Highly Voted 2 years ago
Selected Answer: D
D is the correct answer.. B is wrong answer From aws documentation: Q: Which AWS accounts can I connect to IAM Identity Center? You can add any AWS account managed using AWS Organizations to IAM Identity Center. You need to enable all features in your organizations to manage your accounts single sign-on.
upvoted 17 times
carpa_jo
1 year, 2 months ago
Source: https://aws.amazon.com/iam/identity-center/faqs/#product-faqs#iam-identity-center-faqs#identity-sources-and-applications-support
upvoted 1 times
...
...
29fb203
Most Recent 1 week, 3 days ago
Selected Answer: B
All features is not required.
upvoted 1 times
...
LeoSantos121212121212121
1 week, 3 days ago
Selected Answer: B
Lower cost compared to AWS Managed Microsoft AD, since AD Connector does not require an additional managed directory service. Also, is answer D AWS Organizations does not require "all features" for IAM Identity Center to work with AD Connector. "All features" is needed for SCPs and governance, not for SSO setup.
upvoted 1 times
...
shmoeee
1 month, 3 weeks ago
Selected Answer: D
"Need to turn on all features" didn't sound cost effective...but apparently it's a requirement to provide SSO
upvoted 1 times
...
JOJO9
3 months ago
Selected Answer: B
Question asks "MOST cost-effectively". Turning on all features is free of charge but used resources will make up a cost. D is wrong because: enabling All Features in AWS Organizations introduces governance tools that the company does not require, making it less cost-effective than B.
upvoted 3 times
...
amministrazione
6 months, 3 weeks ago
D. Create an organization in AWS Organizations. Turn on all features for the organization. Create and configure an AD Connector to connect to the company’s on-premises Active Directory. Configure IAM Identity Center and set the AD Connector as the identity source. Create permission sets and map them to the existing groups within the company’s Active Directory.
upvoted 1 times
pk0619
3 months ago
You need to enable all features for the organization to set up single sign-on for accounts.
upvoted 1 times
...
...
gofavad926
1 year ago
Selected Answer: B
B, Turn on the IAM Identity Center feature in Organizations... similar to D, but without enabling directy the SSO, you can't configure it...
upvoted 2 times
helloworldabc
6 months, 2 weeks ago
just D
upvoted 1 times
...
...
8608f25
1 year, 1 month ago
Selected Answer: D
Option D is the best because AWS FAQs asked the following question and answered: "Which AWS accounts can I connect to IAM Identity Center? You can add any AWS account managed using AWS Organizations to IAM Identity Center. You need to enable all features in your organizations to manage your accounts single sign-on." Link: https://aws.amazon.com/iam/identity-center/faqs/#product-faqs#iam-identity-center-faqs#identity-sources-and-applications-support. With the clarification that enabling all features in AWS Organizations is necessary for integrating with IAM Identity Center, Option D becomes the most accurate and compliant solution. It correctly combines the need to enable all features in AWS Organizations with the use of an AD Connector for a direct connection to the company’s on-premises Active Directory, which remains the most cost-effective way to leverage existing Active Directory credentials for AWS console access.
upvoted 1 times
...
LazyAutonomy
1 year, 1 month ago
Selected Answer: D
Most cost effective is D. But C is also technically a valid solution that meets all the other requirements. A two way trust means AD users in the on-premise AD can be added to AD groups in the AWS-managed AD.
upvoted 1 times
...
ninomfr64
1 year, 2 months ago
Selected Answer: D
A = you do not turn on AWS IdC feature only in AWS Orgs. It is either Consolidation billing or All features B = same as above C = requirements is to login users based on-premise AD, for this there is no need to AWS Managed AD with a local domain/directory and 2-way trust. AD Connector is enough and cheaper D = correct
upvoted 5 times
...
marszalekm
1 year, 2 months ago
I love such questions, while both B and D seems reasonable, I thinking more about B because of this https://docs.aws.amazon.com/singlesignon/latest/userguide/get-set-up-for-idc.html
upvoted 1 times
...
Russs99
1 year, 3 months ago
Selected Answer: B
you can absolutely use an AD Connector as the identity source for AWS IAM Identity Center without turning on all features in your AWS organization. In fact, it's the most cost-effective and recommended approach if you only need single sign-on functionality with your existing on-premises Active Directory
upvoted 3 times
...
holymancolin
1 year, 3 months ago
Selected Answer: D
https://docs.aws.amazon.com/singlesignon/latest/userguide/prereq-orgs.html ```If you've already set up AWS Organizations and are going to add IAM Identity Center to your organization, make sure that all AWS Organizations features are enabled. When you create an organization, enabling all features is the default.```
upvoted 4 times
...
severlight
1 year, 4 months ago
Selected Answer: D
see dev112233xx's answer
upvoted 1 times
...
Tofu13
1 year, 5 months ago
Selected Answer: D
https://docs.aws.amazon.com/singlesignon/latest/userguide/get-started-prereqs-considerations.html#:~:text=if%20you've%20already%20set%20up%20aws%20organizations%2C%20make%20sure%20that%20all%20features%20are%20enabled.
upvoted 2 times
...
[Removed]
1 year, 8 months ago
Selected Answer: B
i think it's b because having all the features enabled is not a requirement, otherwise it could incour in more charges. the features are not enabled by default , you have to go one by one or select all to enable them
upvoted 1 times
ninomfr64
1 year, 2 months ago
Actually not. AWS Org has 2 feature modes: All features enabled (default) and Consolidated billing. AWS Orgs is free of charge regardless feature mode select see Billing section in the https://aws.amazon.com/organizations/faqs/
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago