Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 319 discussion

A company’s solutions architect needs to provide secure Remote Desktop connectivity to users for Amazon EC2 Windows instances that are hosted in a VPC. The solution must integrate centralized user management with the company's on-premises Active Directory. Connectivity to the VPC is through the internet. The company has hardware that can be used to establish an AWS Site-to-Site VPN connection.

Which solution will meet these requirements MOST cost-effectively?

  • A. Deploy a managed Active Directory by using AWS Directory Service for Microsoft Active Directory. Establish a trust with the on-premises Active Directory. Deploy an EC2 instance as a bastion host in the VPC. Ensure that the EC2 instance is joined to the domain. Use the bastion host to access the target instances through RDP.
  • B. Configure AWS IAM Identity Center (AWS Single Sign-On) to integrate with the on-premises Active Directory by using the AWS Directory Service for Microsoft Active Directory AD Connector. Configure permission sets against user groups for access to AWS Systems Manager. Use Systems Manager Fleet Manager to access the target instances through RDP.
  • C. Implement a VPN between the on-premises environment and the target VPEnsure that the target instances are joined to the on-premises Active Directory domain over the VPN connection. Configure RDP access through the VPN. Connect from the company’s network to the target instances.
  • D. Deploy a managed Active Directory by using AWS Directory Service for Microsoft Active Directory. Establish a trust with the on-premises Active Directory. Deploy a Remote Desktop Gateway on AWS by using an AWS Quick Start. Ensure that the Remote Desktop Gateway is joined to the domain. Use the Remote Desktop Gateway to access the target instances through RDP.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Pilot
Highly Voted 5 months, 2 weeks ago
I think this question is not really about Active Directory or AD Connector. A secure VPN connection is all you need in this question. The company has hardware can be used to establish an AWS S2S connection. In order to have a secure connection, the first thing you have to do is to implement a VPN connection between on-premise and target VPC. So C is the answer.
upvoted 16 times
...
Sab
Highly Voted 6 months ago
Selected Answer: B
You cannot join an EC2 to On-prem AD just over the VPN. You should be having an AD connector for the same. https://aws.amazon.com/blogs/security/how-to-connect-your-on-premises-active-directory-to-aws-using-ad-connector/
upvoted 9 times
bjexamprep
4 months, 2 weeks ago
Can you provide the link saying why EC2 cannot join an onprem AD over VPN? As long as the network connectivity is created, I don't see a problem for an EC2 instance to join an on-prem domain.
upvoted 4 times
tmlong18
4 months ago
https://aws.amazon.com/tw/blogs/networking-and-content-delivery/integrating-your-directory-services-dns-resolution-with-amazon-route-53-resolvers/ You should config DHCP and DNS
upvoted 1 times
bjexamprep
1 month, 3 weeks ago
The article is about "Integrating your Directory Service’s DNS resolution with Amazon Route 53 Resolvers". It doesn't mean an EC2 cannot join an onprem AD. If AWS says you can't use onprem AD even the network is connected, that is really a terrible design. I don't think AWS can design it that way.
upvoted 2 times
...
bjexamprep
1 month, 3 weeks ago
AWS might recommend the consumers to use Active directory connect, but cannot deny using on-prem ADDS directly. And as long as the network is connected, all you need is to create a custom DHCP option set pointing to that ADDS.
upvoted 2 times
...
...
...
...
red_panda
Most Recent 1 week, 1 day ago
Selected Answer: C
For me it's C. No need to Managed AD Connector. We have already a VPN, so we can leverage to spend less.
upvoted 1 times
...
seetpt
2 weeks, 1 day ago
Selected Answer: B
B for me
upvoted 1 times
...
titi_r
1 month ago
Selected Answer: C
Ans C. If the VPC and the on-prem network are connected, there is no need for AD Connector, it works like any other interconnected networks. The EC2s must have DNS resolution, usually those will be the AD domain controllers (which in this case are located on prem).
upvoted 1 times
...
yog927
2 months ago
Selected Answer: B
It is B and not C. You need to AD connector to connect to on-premises AD. Did not find any article that suggests you can connect to on-premises AD over VPN without using AD connector or Active directory trust.
upvoted 2 times
joseribas89
1 month, 3 weeks ago
If you just change your DHCP on AWS and put the domain IP from your on-premise AD, yes you can, but I think AWS expects that you use SSM for that, so B is the answer, but again, you can definitely connect your all environment EC2 to your On-Premise AD with just VPN
upvoted 1 times
...
...
cloudchica
3 months ago
B is the right answer.
upvoted 1 times
...
ele
3 months ago
Selected Answer: C
C is the answer. most cost-effective.
upvoted 2 times
...
arberod
3 months ago
Selected Answer: C
It is C
upvoted 2 times
...
07c2d2a
3 months, 1 week ago
B is the answer. C would be the cheapest option, BUT it say's they currently access over the internet. This means that they don't have DNS appliances setup. Those are not included in the answer and they also cost money, making B the only real option here.
upvoted 2 times
...
vibzr2023
4 months ago
Answer: B Keyword "AWS IAM Identity Center (AWS Single Sign-On) "
upvoted 1 times
...
career360guru
4 months, 1 week ago
Selected Answer: C
C is the cheapest option. D is possible but there are hidden cost like Windows server licensing cost for each subnet + Secrets Manager cost.
upvoted 5 times
JMAN1
4 months ago
I am following your answer. Windows connect question is really hard for me. I have no experience.
upvoted 1 times
...
...
severlight
6 months ago
Selected Answer: B
B seems cheaper than D
upvoted 3 times
...
Andres123456
6 months, 1 week ago
Selected Answer: B
https://aws.amazon.com/blogs/mt/console-based-access-to-windows-instances-using-aws-systems-manager-fleet-manager/
upvoted 4 times
...
Russs99
6 months, 2 weeks ago
Selected Answer: D
D is the cheapest option: | A | AWS Directory Service for Microsoft Active Directory: $0.90 per directory per month + EC2 instance: $0.006 per hour | | B | AWS IAM Identity Center: $0.25 per user per month + AWS Directory Service for Microsoft Active Directory AD Connector: $0.25 per directory per month + AWS Systems Manager: $0.033 per hour per instance | | C | VPN connection: Varies depending on the provider and the type of VPN connection + Target instances: $0.006 per hour per instance | | D | AWS Directory Service for Microsoft Active Directory: $0.90 per directory per month + Remote Desktop Gateway Quick Start: No additional cost |
upvoted 1 times
marians86
6 months, 1 week ago
AWS Directory Service for Microsoft Active Directory in Ireland costs about 92 $ per month, not 0.90
upvoted 1 times
...
...
airgead
6 months, 2 weeks ago
Selected Answer: D
The correct answer is D - Remote Desktop Gateway for remote access to EC2 using quick start (https://docs.aws.amazon.com/quickstart/latest/rd-gateway/welcome.html) - Managed AD -> On premise AD using Trust Relationship Centralised user management and leverages the existing hardware to establish an AWS Site-to-Site VPN connection.
upvoted 1 times
...
s61
6 months, 2 weeks ago
Selected Answer: C
S2S VPN ($36 p/m) is cheaper than using AD Connector (36.50 p/m)
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...