ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 296 - SAP-C02 discussion

Report
Export

A solutions architect has implemented a SAML 2 0 federated identity solution with their company's on-premises identity provider (IdP) to authenticate users' access to the AWS environment. When the solutions architect tests authentication through the federated identity web portal, access to the AWS environment is granted However when test users attempt to authenticate through the federated identity web portal, they are not able to access the AWS environment Which items should the solutions architect check to ensure identity federation is properly configured? (Select THREE)

A.
The 1AM user's permissions policy has allowed the use of SAML federation for that user
Answers
A.
The 1AM user's permissions policy has allowed the use of SAML federation for that user
B.
The 1AM roles created for the federated users' or federated groups' trust policy have set the SAML provider as the principal
Answers
B.
The 1AM roles created for the federated users' or federated groups' trust policy have set the SAML provider as the principal
C.
Test users are not in the AWSFederatedUsers group in the company's IdP
Answers
C.
Test users are not in the AWSFederatedUsers group in the company's IdP
D.
The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the 1AM role, and the SAML assertion from IdP
Answers
D.
The web portal calls the AWS STS AssumeRoleWithSAML API with the ARN of the SAML provider, the ARN of the 1AM role, and the SAML assertion from IdP
E.
The on-premises IdP's DNS hostname is reachable from the AWS environment VPCs
Answers
E.
The on-premises IdP's DNS hostname is reachable from the AWS environment VPCs
F.
The company's IdP defines SAML assertions that properly map users or groups in the company to 1AM roles with appropriate permissions
Answers
F.
The company's IdP defines SAML assertions that properly map users or groups in the company to 1AM roles with appropriate permissions
Suggested answer: B, D, F
asked 16/09/2024
Jose Osnayo
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first