AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A global corporation is migrating its on-premises data center to AWS. The on-premises environment relies heavily on Microsoft Active Directory (AD) for user authentication and group management. The migration includes a large number of Windows Server-based applications that are domain-joined and require AD authentication. The company uses AWS Organizations to manage dozens of AWS accounts.

The solutions architect must design an identity solution that meets the following requirements:

  • On-premises AD must remain the authoritative source of truth for all user identities.
  • Users must use their existing corporate credentials for SSO access to both the migrated Windows applications on EC2 and for federated access to the AWS Management Console across all accounts.
  • The solution must be resilient to intermittent network connectivity disruptions between the on-premises data center and AWS.
  • The solution should avoid the creation and management of duplicate IAM users.

Which solution should the architect recommend?

  • Deploy AWS Managed Microsoft AD and establish a two-way forest trust with the on-premises AD. Configure AWS IAM Identity Center to use the AWS Managed Microsoft AD as the identity source.

  • Deploy Simple AD for the Windows applications to join. Create individual IAM users for all administrators and attach policies to grant them AWS Management Console access.

  • Establish a SAML 2.0 trust between an on-premises AD FS instance and AWS IAM. Manually create IAM roles for console access and join the EC2 instances to the on-premises domain via AWS Site-to-Site VPN.

  • Deploy AD Connector in the VPC and connect it to the on-premises AD. Configure AWS IAM Identity Center to use the AD Connector as the identity source.

AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot