AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A large enterprise uses Microsoft Entra ID as its corporate identity provider (IdP). The company operates a multi-account AWS environment under AWS Organizations and must give developers and data scientists access to specific roles in multiple AWS accounts. Security requirements include:

  • Manage user identities and group memberships only in Entra ID.
  • Implement attribute-based access control (ABAC) in AWS by tagging the federated session with the user's attributes.
  • Enforce least privilege, scale to hundreds of accounts, and avoid creating individual IAM users.

Which approach best meets these requirements?

  • Deploy AWS Directory Service AD Connector in a shared VPC, establish a trust with Entra ID, and have IAM roles in target accounts trust the directory for access.

  • In each AWS account, create one IAM role for every Entra ID group that needs access and map the groups to those roles through separate SAML configurations.

  • Automate the deployment of an identical SAML 2.0 identity provider (using Entra ID metadata) in every AWS account-e.g., with AWS CloudFormation StackSets. Configure Entra ID to pass user attributes as SAML assertions mapped to PrincipalTag session tags. In each account, create a single generic IAM role that trusts its local SAML provider and uses aws:PrincipalTag conditions in its policy to implement ABAC.

  • Create an OpenID Connect (OIDC) federation between Entra ID and a central AWS account and instruct users to call sts:AssumeRole with their OIDC tokens to access the required AWS roles.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot