AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An organization with multiple AWS accounts is migrating from long-lived IAM users to federated access using its existing Okta SAML 2.0 identity provider. DevOps engineers must sign in with the AWS CLI v2 and receive short-lived credentials for different roles in those accounts, without maintaining custom scripts or access keys. Which AWS service or feature most directly meets these requirements?
Create cross-account IAM users and rotate their access keys with AWS Secrets Manager
Use Amazon Cognito user pools with Okta as an OpenID Connect external IdP
Configure AWS IAM Identity Center and connect it to the Okta SAML 2.0 identity provider
Issue AWS STS long-term session tokens by calling GetSessionToken from each developer's workstation
AWS IAM Identity Center (successor to AWS Single Sign-On) can be connected to an external SAML 2.0 IdP such as Okta. After the linkage is configured, users authenticate with the IdP and the AWS CLI v2 natively performs an IAM Identity Center login flow, automatically receiving short-lived role credentials for any authorized account. Amazon Cognito user pools focus on application authentication, not workforce access through the CLI. Creating cross-account IAM users still leaves long-lived access keys to manage, and AWS STS GetSessionToken requires those keys to request temporary credentials, so it does not eliminate their administration.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS IAM Identity Center?
Open an interactive chat with Bash
What is SAML 2.0 and how does it work with Okta?
Open an interactive chat with Bash
How does the AWS CLI v2 obtain short-lived credentials through IAM Identity Center?
Open an interactive chat with Bash
What is AWS IAM Identity Center?
Open an interactive chat with Bash
What is SAML 2.0, and how does AWS support it?
Open an interactive chat with Bash
How does federated access with AWS CLI v2 work?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .