Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 290

    A company controls user access by using IAM users and groups in AWS accounts across an organization in AWS Organizations. The company uses an external identity provider (IdP) for workforce single sign-on (SSO).

    The company needs to implement a solution to provide a single management portal to access accounts within the organization. The solution must support the external IdP as a federation source.

    Which solution will meet these requirements?

    • Enable AWS IAM Identity Center. Specify the external IdP as the identity source.

    • Enable federation with AWS Identity and Access Management (IAM). Specify the external IdP as the identity source.

    • Migrate to Amazon Verified Permissions. Implement fine-grained access to AWS by using policy-based access control (PBAC).

    • Migrate users to AWS Directory Service. Use AWS Control Tower to centralize security across the organization.


    シャッフルモード