AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An organization with multiple AWS accounts is migrating from long-lived IAM users to federated access using its existing Okta SAML 2.0 identity provider. DevOps engineers must sign in with the AWS CLI v2 and receive short-lived credentials for different roles in those accounts, without maintaining custom scripts or access keys. Which AWS service or feature most directly meets these requirements?

  • Create cross-account IAM users and rotate their access keys with AWS Secrets Manager

  • Use Amazon Cognito user pools with Okta as an OpenID Connect external IdP

  • Configure AWS IAM Identity Center and connect it to the Okta SAML 2.0 identity provider

  • Issue AWS STS long-term session tokens by calling GetSessionToken from each developer's workstation

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot