AWS Certified Developer Associate DVA-C02 Practice Question
An enterprise has mandated that their cloud-hosted applications authenticate users from the on-premises directory service without duplicating sensitive credentials. Which approach should be employed to meet this requirement while leveraging the organization's existing user directory?
Migrate the on-premises directory service users to a cloud directory service with User Pools.
Generate temporary access credentials for users via a token service to authenticate against the on-premises directory service.
Integrate the application through federation using SAML 2.0 with the organization's existing identity management system.
Implement application-side user authentication controls using the Access Control List (ACL) feature of a cloud directory service.
The correct approach is to integrate the cloud application with the on-premises directory service using a federation protocol such as SAML 2.0. IAM supports federation with SAML, which allows users to authenticate using their existing corporate credentials without storing those credentials in the cloud. While Amazon Cognito can also perform SAML federation, using IAM roles with SAML assertions is the most direct way to extend an established enterprise directory such as Active Directory to AWS resources. The other options either duplicate credentials or rely on mechanisms that do not satisfy the stated requirement of federating with the existing directory.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAML 2.0 and how does it enable federation?
Open an interactive chat with Bash
Why is using IAM roles with SAML better for extending enterprise directories to AWS?
Open an interactive chat with Bash
How does Amazon Cognito support SAML federation, and why isn’t it used here?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .