AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your organization uses IAM Identity Center with AWS Managed Microsoft AD as the identity source. More than 300 user and group assignments span 150 AWS accounts and dozens of permission sets. The company will retire Active Directory and adopt Okta as its workforce identity platform. During a brief maintenance window, you must switch IAM Identity Center to use Okta without leaving users locked out of the AWS accounts for an extended period.

Which approach will meet these requirements?

  • Use the ListAccountAssignments API to export the current assignments, provision identical users and groups in Okta through SCIM, change the identity source to the external IdP, and then call CreateAccountAssignment in an automated script to restore each assignment.

  • Increase the IAM Identity Center session duration to keep existing sessions active, switch the identity source to Okta, and allow sessions to expire naturally after the cutover.

  • Change the identity source directly to the external IdP and rely on Okta to send matching SAML assertions so that IAM Identity Center keeps the existing assignments.

  • First switch the identity source from Active Directory to the built-in Identity Center directory to preserve assignments, and then switch to Okta as the external IdP.

AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot