AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company federates employee access to multiple AWS accounts by using a SAML 2.0 identity provider (IdP). Each account still has the default 1-hour maximum session duration for the IAM roles that employees assume through SAML. Compliance now requires 2-hour sessions, so the IdP was updated to include a DurationSeconds=7200 attribute. Since the change, users receive an AccessDenied error when attempting to sign in. Which action will allow successful federation while meeting the 2-hour session requirement?

  • Remove any duration attribute so the default 1-hour session length is applied automatically.

  • Add the parameter --duration-seconds 7200 to all AWS CLI profiles used by the developers.

  • Rename the attribute in the SAML assertion to SessionDuration and increase each role's Maximum session duration setting to 7,200 seconds.

  • Keep the DurationSeconds attribute but raise every role's Maximum session duration to 12 hours.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot