exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 196 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 196
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A large corporation is creating a multi-account strategy and needs to determine how its employees should access the AWS Infrastructure.
Which of the following solutions would provide the MOST scalable solution?

  • A. Create dedicated IAM users within each AWS account that employees can assume though federation based upon group membership in their existing identity provider.
  • B. Use a centralized account with IAM roles that employees can assume through federation with their existing identity provider. Use cross-account roles to allow the federated users to assume their target role in the resource accounts.
  • C. Configure the AWS Security Token Service to use Kerberos tokens so that users can use their existing corporate user names and passwords to access AWS resources directly.
  • D. Configure the IAM trust policies within each account's role to set up a trust back to the corporation's existing identity provider, allowing users to assume the role based off their SAML token.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sanjaym
Highly Voted 3 years, 7 months ago
B 100%
upvoted 12 times
...
[Removed]
Highly Voted 3 years, 8 months ago
B: https://d0.awsstatic.com/aws-answers/AWS_Multi_Account_Security_Strategy.pdf
upvoted 5 times
...
Raphaello
Most Recent 1 year, 3 months ago
Selected Answer: B
Correct answer is B.
upvoted 1 times
...
epomatti
1 year, 8 months ago
There is no such thing as "cross-account Roles". An IAM Role exists only in a single account.
upvoted 1 times
...
ITGURU51
2 years, 1 month ago
Federated identities in AWS assume roles for temporary access to resources. B
upvoted 1 times
...
awssazure
2 years, 8 months ago
Selected Answer: B
B all the way
upvoted 1 times
...
sapien45
2 years, 10 months ago
Selected Answer: B
Source : AWS Best Pratices SRA https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/account-structure.html
upvoted 1 times
...
alghoundar
3 years, 4 months ago
agreed B is the best choice.
upvoted 1 times
...
Radhaghosh
3 years, 4 months ago
B is Correct
upvoted 1 times
...
munish3420
3 years, 6 months ago
Selected Answer: B
A is not a scalable solution. B is correct answer here
upvoted 3 times
...
IMAHM
3 years, 6 months ago
Answer is B
upvoted 2 times
...
DerekKey
3 years, 7 months ago
A - wrong - you assume a role, not a user account
upvoted 2 times
...
Hungdv
3 years, 7 months ago
Answer is B
upvoted 3 times
...
Edgecrusher77
3 years, 7 months ago
Answer is B
upvoted 3 times
...
cldy
3 years, 8 months ago
B. Answer
upvoted 4 times
...
Hudda
3 years, 8 months ago
A is final answer? friends pls confirm.
upvoted 1 times
...
Hudda
3 years, 8 months ago
i think so too. any other idea friends ?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...