AWS Certified Developer Associate DVA-C02 Practice Question
An enterprise has mandated that their cloud-hosted applications authenticate users from the on-premises directory service without duplicating sensitive credentials. Which approach should be employed to meet this requirement while leveraging the organization's existing user directory?
Generate temporary access credentials for users via a token service to authenticate against the on-premises directory service.
Migrate the on-premises directory service users to a cloud directory service with User Pools.
Implement application-side user authentication controls using the Access Control List (ACL) feature of a cloud directory service.
Integrate the application through federation using SAML 2.0 with the organization's existing identity management system.
The correct approach is to integrate the cloud application with the on-premises directory service using a federation protocol such as SAML 2.0. IAM supports federation with SAML, which allows users to authenticate using their existing corporate credentials without storing those credentials in the cloud. While Cognito is also a service that supports federation, IAM with SAML is specifically designed to work seamlessly with corporate directories like Active Directory and is hence the better-suited choice for this particular use case. The other options mentioned do not directly address the requirement of federating with an existing on-premises directory service.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML 2.0 and how does it work?
Open an interactive chat with Bash
What is the role of IAM in AWS when using SAML 2.0?
Open an interactive chat with Bash
What is the benefit of using federated authentication over direct credential storage?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access