ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 310 - SCS-C01 discussion

Report
Export

You are working for a company and been allocated the task for ensuring that there is a federated authentication mechanism setup between AWS and their On-premise Active Directory. Which of the following are important steps that need to be covered in this process? Choose 2 answers from the options given below.

Please select:

A.
Ensure the right match is in place for On-premise AD Groups and IAM Roles.
Answers
A.
Ensure the right match is in place for On-premise AD Groups and IAM Roles.
B.
Ensure the right match is in place for On-premise AD Groups and IAM Groups.
Answers
B.
Ensure the right match is in place for On-premise AD Groups and IAM Groups.
C.
Configure AWS as the relying party in Active Directory
Answers
C.
Configure AWS as the relying party in Active Directory
D.
Configure AWS as the relying party in Active Directory Federation services
Answers
D.
Configure AWS as the relying party in Active Directory Federation services
Suggested answer: A, D

Explanation:

The AWS Documentation mentions some key aspects with regards to the configuration of Onpremise AD with AWS One is the Groups configuration in AD Active Directory Configuration Determining how you will create and delineate your AD groups and IAM roles in AWS is crucial to how you secure access to your account and manage resources. SAML assertions to the AWS environment and the respective IAM role access will be managed through regular expression (regex) matching between your on-premises AD group name to an AWS IAM role.

One approach for creating the AD groups that uniquely identify the AWS IAM role mapping is by selecting a common group naming convention. For example, your AD groups would start with an identifier, for example, AWS-, as this will distinguish your AWS groups from others within the organization. Next include the 12-digitAWS account number. Finally, add the matching role name within the AWS account. Here is an example:

And next is the configuration of the relying party which is AWS

ADFS federation occurs with the participation of two parties; the identity or claims provider (in this case the owner of the identity repository - Active Directory) and the relying party, which is another application that wishes to outsource authentication to the identity provider; in this case Amazon Secure Token Service (STS). The relying party is a federation partner that is represented by a claims provider trust in the federation service. Option B is invalid because AD groups should not be matched to IAM Groups

Option C is invalid because the relying party should be configured in Active Directory Federation services For more information on the federated access, please visit the following URL:

1 https://aws.amazon.com/blogs/security/aws-federated-authentication-with-active-directoryfederation-services-ad-fs/The correct answers are: Ensure the right match is in place for On-premise AD Groups and IAMRoles., Configure AWS as the relying party in Active Directory Federation servicesSubmit your Feedback/Queries to our Experts

asked 16/09/2024
mahdis khaledi
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first