Q399.A financial company with multiple departments wants to expand its on- premises environment to the AWS Cloud. The company must retain centralized access control using an existing on- premises Active Directory (AD) service.<

欢迎免费使用小程序搜题/刷题/查看解析,提升学历,成考自考报名,论文代写、论文查重请加客服微信skr-web


Q399.A financial company with multiple departments wants to expand its on- premises environment to the AWS Cloud. The company must retain centralized access control using an existing on- premises Active Directory (AD) service.
Each department should be allowed to create AWS accounts with preconfigured networking and should have access to only a specific list of approved services. Departments are not permitted to have account administrator permissions.What should a solutions architect do to meet these security requirements?

A.Configure AWS Identity and Access Management (IAM) with a SAML identity provider (IdP) linked to the on-premises Active Directory and create a role to
Grant access.Configure AWS Organizations with SCPs and create new member accounts.Use AWS CloudFormation templates to configure the member account networking. B.Deploy an AWS Control Tower landing zone. Create an AD Connector linked to the on-premises Active Directory.Change the identity source in AWS Single Sign-On to use Active Directory.Allow department administrators to use Account Factory to create new member accounts and networking.Grant the departments AWS power user permissions on the created accounts. C.Deploy an Amazon Cloud Directory.Create a two-way trust relationship with the on-premises Active Directory and create a role to grant access.Set up an AWS Service Catalog to use AWS CloudFormation templates to create the new member accounts and networking.Use IAM roles to allow access to approved AWS services. D.Configure AWS Directory Service for Microsoft Active Directory with AWS Single Sign-On.Join the service to the on-premises Active Directory.Use AWS CloudFormation to create new member accounts and networking.Use IAM roles to allow access to approved AWS services.
正确答案B
访客
邮箱
网址

通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作


  • 自动写文案
  • 自动写小说
  • 马上扫码让Ai帮你完成工作
通用的占位符缩略图

人工智能机器人,扫码免费帮你完成工作

  • 自动写论文
  • 自动写软件
  • 我不是人,但是我比人更聪明,我是强大的Ai
Top