ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 311 - SCS-C01 discussion

Report
Export

Which technique can be used to integrate AWS IAM (Identity and Access Management) with an onpremise LDAP (Lightweight Directory Access Protocol) directory service? Please select:

A.
Use an IAM policy that references the LDAP account identifiers and the AWS credentials.
Answers
A.
Use an IAM policy that references the LDAP account identifiers and the AWS credentials.
B.
Use SAML (Security Assertion Markup Language) to enable single sign-on between AWS and LDAP.
Answers
B.
Use SAML (Security Assertion Markup Language) to enable single sign-on between AWS and LDAP.
C.
Use AWS Security Token Service from an identity broker to issue short-lived AWS credentials.
Answers
C.
Use AWS Security Token Service from an identity broker to issue short-lived AWS credentials.
D.
Use IAM roles to automatically rotate the IAM credentials when LDAP credentials are updated.
Answers
D.
Use IAM roles to automatically rotate the IAM credentials when LDAP credentials are updated.
Suggested answer: B

Explanation:

On the AWS Blog site the following information is present to help on this context The newly released whitepaper. Single Sign-On: Integrating AWS, OpenLDAP, and Shibboleth, will help you integrate your existing LDAP-based user directory with AWS. When you integrate your existing directory with AWS, your users can access AWS by using their existing credentials. This means that your users don't need to maintain yet another user name and password just to access AWS resources.

Option A.C and D are all invalid because in this sort of configuration, you have to use SAML to enable single sign on. For more information on integrating AWS with LDAP for Single Sign-On, please visit the following URL:

https://aws.amazon.eom/blogs/security/new-whitepaper-sinEle-sign-on-inteErating-aws-openldapand-shibboleth/lThe correct answer is: Use SAML (Security Assertion Markup Language) to enable single sign-onbetween AWS and LDAP. Submit your Feedback/Queries to our Experts

asked 16/09/2024
Andrew dela Cruz
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first