Examtopics

AWS Certified Solutions Architect - Associate
  • Topic 1 Question 484

    A company wants to move from many standalone AWS accounts to a consolidated, multi-account architecture. The company plans to create many new AWS accounts for different business units. The company needs to authenticate access to these AWS accounts by using a centralized corporate directory service.

    Which combination of actions should a solutions architect recommend to meet these requirements?

    2 つ選択
    • Create a new organization in AWS Organizations with all features turned on. Create the new AWS accounts in the organization.

    • Set up an Amazon Cognito identity pool. Configure AWS IAM Identity Center (AWS Single Sign-On) to accept Amazon Cognito authentication.

    • Configure a service control policy (SCP) to manage the AWS accounts. Add AWS IAM Identity Center (AWS Single Sign-On) to AWS Directory Service.

    • Create a new organization in AWS Organizations. Configure the organization's authentication mechanism to use AWS Directory Service directly.

    • Set up AWS IAM Identity Center (AWS Single Sign-On) in the organization. Configure IAM Identity Center, and integrate it with the company's corporate directory service.


    シャッフルモード