exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 704 discussion

Exam question from Amazon's AWS-SysOps
Question #: 704
Topic #: 1
[All AWS-SysOps Questions]

An organization with a large IT department has decided to migrate to AWS. With different job functions in the IT department, it is not desirable to give all users access to all AWS resources. Currently the organization handles access via LDAP group membership.
What is the BEST method to allow access using current LDAP credentials?

  • A. Create an AWS Directly Service Simple AD. Replicate the on-premises LDAP directory to Simple AD.
  • B. Create a Lambda function to read LDAP groups and automate the creation of IAM users.
  • C. Use AWS CloudFormation to create IAM roles. Deploy Direct Connect to allow access to the on-premises LDAP server.
  • D. Federate the LDAP directory with IAM using SAML. Create different IAM roles to correspond to different LDAP groups to limit permissions.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_federated-users.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Hizumi
Highly Voted 2 years, 7 months ago
Answer is D based on the link provided in the solution, it talks about federating users using SAML from any system, including LDAP.
upvoted 5 times
...
albert_kuo
Most Recent 9 months, 3 weeks ago
Selected Answer: D
The BEST method to allow access using current LDAP credentials in the given scenario is to federate the LDAP directory with IAM using SAML and create different IAM roles corresponding to different LDAP groups to limit permissions (Option D). This approach combines the benefits of LDAP integration, group-based permissions, and centralized IAM management.
upvoted 1 times
...
lartex
2 years, 6 months ago
D for me
upvoted 3 times
...
ahaffar
2 years, 6 months ago
Answer A is more suitbale since the option D requires to have custom identity broker application and is used where internal application needs to have access to AWS resource. https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_federated-users.html#id_roles_common-scenarios_federated-users-idbroker
upvoted 1 times
Akinwaleo
1 year ago
large IT department HAS DECIDED to migrate to AWS, so they're still on-premise
upvoted 1 times
...
...
TroyMcLure
2 years, 7 months ago
Correct Answer: A Since the organization already handles access via LDAP on-premises, AWS Simple AD would be a good alternative with less effort.
upvoted 1 times
TroyMcLure
2 years, 6 months ago
Thinking twice, I believe that "D" is right.
upvoted 2 times
...
...
RicardoD
2 years, 7 months ago
D is the answer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago